Re: [Freeipa-users] IPA 4.2.0 / CentOS 7: krb5kdc: Server error - while fetching master key K/M for realm

2016-02-18 Thread Torsten Harenberg
Sorry for self-replying.

I should have mentioned that we already went through:

http://www.freeipa.org/page/Troubleshooting#Service_does_not_start

But it turned out that a simple

ipactl stop
ipactl start

helped.

Surprisingly, the service does not start correctly at boot time, but
starting it through ipactl afterwards brings it up without any complaint.

Best regards

  Torsten

-- 
Dr. Torsten Harenberg harenb...@physik.uni-wuppertal.de
Bergische Universitaet
Fakultät 4 - Physik   Tel.: +49 (0)202 439-3521
Gaussstr. 20  Fax : +49 (0)202 439-2811
42097 Wuppertal

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

[Freeipa-users] IPA 4.2.0 / CentOS 7: krb5kdc: Server error - while fetching master key K/M for realm

2016-02-18 Thread Torsten Harenberg
Dear all,

we run a pair of IPA servers:

a master running on FC 21 and a slave running on CentOS release 7.2.1511.

krb5kdc: Server error - while fetching master key K/M for realm
PLEIADES.UNI-WUPPERTAL.DE

To handle CVE-2015-7547, we upgraded both systems (with a simple "yum
update"). The master came up fine, the slave, however, seems not to work
after the upgrade.

The web server did not start and we tackled that down to slapd not
working and this seems not to work as krb5kdc was not enabled anymore in
systemctl.

So we did a

systemctl enable krb5kdc

and rebooted once again, but Kerberos does not start with:


krb5kdc: Server error - while fetching master key K/M for realm
PLEIADES.UNI-WUPPERTAL.DE

and ideas how to proceed?

Thanks

  Torsten

-- 
Dr. Torsten Harenberg harenb...@physik.uni-wuppertal.de
Bergische Universitaet
Fakultät 4 - Physik   Tel.: +49 (0)202 439-3521
Gaussstr. 20  Fax : +49 (0)202 439-2811
42097 Wuppertal

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project