Re: [Freeipa-users] Services missing in web-ui

2016-12-07 Thread Pavel Vomacka
I'm glad that you found it, and I'm sorry, I should have attached the BZ 
in the first mail.



On 12/07/2016 01:26 PM, Troels Hansen wrote:

Sorry. Didn't see this.

https://bugzilla.redhat.com/show_bug.cgi?id=1387782



- On Dec 7, 2016, at 12:43 PM, Troels Hansen  wrote:

Looks great..Pavel, as a RedHat internal, should I create
a ticket to have this fixed in the RedHat version, or does it
already have a internal Red Hat bugzilla case?


- On Dec 7, 2016, at 11:58 AM, Pavel Vomacka
 wrote:

Hello,

it is caused by missing canonical name on services which were
created in older versions of FreeIPA. Fixed ticket here:
https://fedorahosted.org/freeipa/ticket/6397 .

On 12/07/2016 11:48 AM, Fujisan wrote:

And with Firefox 50.0.2.

F.

On Wed, Dec 7, 2016 at 11:46 AM, Fujisan
mailto:fujisa...@gmail.com>> wrote:

I have the same issue with version 4.4.2

$ rpm -qa|grep freeipa
freeipa-server-4.4.2-1.fc25.x86_64
freeipa-python-compat-4.4.2-1.fc25.noarch
freeipa-server-common-4.4.2-1.fc25.noarch
freeipa-common-4.4.2-1.fc25.no
arch
freeipa-server-trust-ad-4.4.2-1.fc25.x86_64
freeipa-client-4.4.2-1.fc25.x86_64
freeipa-client-common-4.4.2-1.fc25.noarch


​F.​


On Wed, Dec 7, 2016 at 11:13 AM, Troels Hansen
mailto:t...@casalogic.dk>> wrote:

I have a strange issue in IPA 4.4.0-12 (RHEL 7.3)


Navigating to Identity -> Services reveals 5
services. 2 cifs, 2 dogtag and one empty line...

cifs/host1.domain@REALM
cifs/host2.domain@REALM
dogtag/ipa01.domain@REALM
dogtag/ipa02.domain@REALM



However, from CLI everything looks OK:

# ipa service-find
---
11 services matched
---
Principal name: ldap/ipa02.domain@REALM
Principal alias: ldap/ipa02.domain@REALM
Certificate: ...
...


Keytab: True

Principal name: ldap/ipa01.domain@REALM
Principal alias: ldap/ipa01.domain@REALM
Certificate: ...
...


Keytab: True

Principal name: HTTP/ipa02.domain@REALM
Principal alias: HTTP/ipa02.domain@REALM
Certificate: 
...



Keytab: True

Principal name: cifs/rhellxudv01.domain@REALM
Principal alias: cifs/rhellxudv01.domain@REALM
Keytab: True



Principal name: cifs/ipa02.domain@REALM
Principal alias: cifs/ipa02.domain@REALM
Keytab: True



Principal name: nfs/profil01.domain@REALM
Principal alias: nfs/profil01.domain@REALM
Keytab: True



Principal name: cifs/ipa01.domain@REALM
Principal alias: cifs/ipa01.domain@REALM
Keytab: True

Principal name: dogtag/ipa02.domain@REALM
Principal alias: dogtag/ipa02.domain@REALM
Keytab: True



Principal name: dogtag/ipa01.domain@REALM
Principal alias: dogtag/ipa01.domain@REALM
Keytab: True



Principal name: cifs/rhellxudv02.domain@REALM
Principal alias: cifs/rhellxudv02.domain@REALM
Keytab: True



Principal name: HTTP/ipa01.domain@REALM
Principal alias: HTTP/ipa01.domain@REALM
Certificate: ..
..
Keytab: True



-
Number of entries returned 11
-




(some lines truncated.)


s... somsthing must be disrupting the view in
web-ui,


Tried in Chrome 43 and IE 11


Looking at what gets requested by the browser at
/ipa/session/json I can see in the json that it
gets the correct content:


result: {count: 11, result: [,…], summary: "11
services matched", truncated: false}
count: 11
  

Re: [Freeipa-users] Services missing in web-ui

2016-12-07 Thread Troels Hansen
Sorry. Didn't see this. 

https://bugzilla.redhat.com/show_bug.cgi?id=1387782 

- On Dec 7, 2016, at 12:43 PM, Troels Hansen  wrote: 

> Looks great.. Pavel, as a RedHat internal, should I create a ticket to 
> have
> this fixed in the RedHat version, or does it already have a internal Red Hat
> bugzilla case?

> - On Dec 7, 2016, at 11:58 AM, Pavel Vomacka  wrote:

>> Hello,

>> it is caused by missing canonical name on services which were created in 
>> older
>> versions of FreeIPA. Fixed ticket here:
>> https://fedorahosted.org/freeipa/ticket/6397 .
>> On 12/07/2016 11:48 AM, Fujisan wrote:

>>> And with Firefox 50.0.2.

>>> F.

>>> On Wed, Dec 7, 2016 at 11:46 AM, Fujisan < fujisa...@gmail.com > wrote:

 I have the same issue with version 4.4.2

 $ rpm -qa|grep freeipa
 freeipa-server-4.4.2-1.fc25.x86_64
 freeipa-python-compat-4.4.2-1.fc25.noarch
 freeipa-server-common-4.4.2-1.fc25.noarch
 freeipa-common-4.4.2-1.fc25.no arch
 freeipa-server-trust-ad-4.4.2-1.fc25.x86_64
 freeipa-client-4.4.2-1.fc25.x86_64
 freeipa-client-common-4.4.2-1.fc25.noarch

 ​F.​

 On Wed, Dec 7, 2016 at 11:13 AM, Troels Hansen < t...@casalogic.dk > wrote:

> I have a strange issue in IPA 4.4.0-12 (RHEL 7.3)

> Navigating to Identity -> Services reveals 5 services. 2 cifs, 2 dogtag 
> and one
> empty line...

> cifs/host1.domain@REALM
> cifs/host2.domain@REALM
> dogtag/ipa01.domain@REALM
> dogtag/ipa02.domain@REALM

> However, from CLI everything looks OK:

> # ipa service-find
> ---
> 11 services matched
> ---
> Principal name: ldap/ipa02.domain@REALM
> Principal alias: ldap/ipa02.domain@REALM
> Certificate: ...
> ...

> Keytab: True

> Principal name: ldap/ipa01.domain@REALM
> Principal alias: ldap/ipa01.domain@REALM
> Certificate: ...
> ...

> Keytab: True

> Principal name: HTTP/ipa02.domain@REALM
> Principal alias: HTTP/ipa02.domain@REALM
> Certificate: 
> ...

> Keytab: True

> Principal name: cifs/rhellxudv01.domain@REALM
> Principal alias: cifs/rhellxudv01.domain@REALM
> Keytab: True

> Principal name: cifs/ipa02.domain@REALM
> Principal alias: cifs/ipa02.domain@REALM
> Keytab: True

> Principal name: nfs/profil01.domain@REALM
> Principal alias: nfs/profil01.domain@REALM
> Keytab: True

> Principal name: cifs/ipa01.domain@REALM
> Principal alias: cifs/ipa01.domain@REALM
> Keytab: True

> Principal name: dogtag/ipa02.domain@REALM
> Principal alias: dogtag/ipa02.domain@REALM
> Keytab: True

> Principal name: dogtag/ipa01.domain@REALM
> Principal alias: dogtag/ipa01.domain@REALM
> Keytab: True

> Principal name: cifs/rhellxudv02.domain@REALM
> Principal alias: cifs/rhellxudv02.domain@REALM
> Keytab: True

> Principal name: HTTP/ipa01.domain@REALM
> Principal alias: HTTP/ipa01.domain@REALM
> Certificate: ..
> ..
> Keytab: True

> -
> Number of entries returned 11
> -

> (some lines truncated.)

> s... somsthing must be disrupting the view in web-ui,

> Tried in Chrome 43 and IE 11

> Looking at what gets requested by the browser at /ipa/session/json I can 
> see in
> the json that it gets the correct content:

> result: {count: 11, result: [,…], summary: "11 services matched", 
> truncated:
> false}
> count: 11
> result: [,…]
> 0: {dn:
> "krbprincipalname=cifs/rhellxudv01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 1: {dn:
> "krbprincipalname=dogtag/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 2: {dn:
> "krbprincipalname=nfs/profil01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 3: {dn:
> "krbprincipalname=cifs/rhellxudv02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 4: {dn:
> "krbprincipalname=dogtag/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 5: {dn:
> "krbprincipalname=HTTP/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 6: {dn:
> "krbprincipalname=cifs/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 7: {dn:
> "krbprincipalname=cifs/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 8: {dn:
> "krbprincipalname=ldap/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 9: {dn:
> "krbprincipalname=HTTP/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> 10: {dn:
> "krbprincipalname=ldap/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
> summary: "11 services matched"
> truncated: false

> So this is obviously only a web-ui problem, but I can't see what causes 
> the
> problem?

> --
> Manage your subscription for the Freeipa-users mailing

Re: [Freeipa-users] Services missing in web-ui

2016-12-07 Thread Troels Hansen
Looks great.. Pavel, as a RedHat internal, should I create a ticket to have 
this fixed in the RedHat version, or does it already have a internal Red Hat 
bugzilla case? 

- On Dec 7, 2016, at 11:58 AM, Pavel Vomacka  wrote: 

> Hello,

> it is caused by missing canonical name on services which were created in older
> versions of FreeIPA. Fixed ticket here:
> https://fedorahosted.org/freeipa/ticket/6397 .
> On 12/07/2016 11:48 AM, Fujisan wrote:

>> And with Firefox 50.0.2.

>> F.

>> On Wed, Dec 7, 2016 at 11:46 AM, Fujisan < fujisa...@gmail.com > wrote:

>>> I have the same issue with version 4.4.2

>>> $ rpm -qa|grep freeipa
>>> freeipa-server-4.4.2-1.fc25.x86_64
>>> freeipa-python-compat-4.4.2-1.fc25.noarch
>>> freeipa-server-common-4.4.2-1.fc25.noarch
>>> freeipa-common-4.4.2-1.fc25.no arch
>>> freeipa-server-trust-ad-4.4.2-1.fc25.x86_64
>>> freeipa-client-4.4.2-1.fc25.x86_64
>>> freeipa-client-common-4.4.2-1.fc25.noarch

>>> ​F.​

>>> On Wed, Dec 7, 2016 at 11:13 AM, Troels Hansen < t...@casalogic.dk > wrote:

 I have a strange issue in IPA 4.4.0-12 (RHEL 7.3)

 Navigating to Identity -> Services reveals 5 services. 2 cifs, 2 dogtag 
 and one
 empty line...

 cifs/host1.domain@REALM
 cifs/host2.domain@REALM
 dogtag/ipa01.domain@REALM
 dogtag/ipa02.domain@REALM

 However, from CLI everything looks OK:

 # ipa service-find
 ---
 11 services matched
 ---
 Principal name: ldap/ipa02.domain@REALM
 Principal alias: ldap/ipa02.domain@REALM
 Certificate: ...
 ...

 Keytab: True

 Principal name: ldap/ipa01.domain@REALM
 Principal alias: ldap/ipa01.domain@REALM
 Certificate: ...
 ...

 Keytab: True

 Principal name: HTTP/ipa02.domain@REALM
 Principal alias: HTTP/ipa02.domain@REALM
 Certificate: 
 ...

 Keytab: True

 Principal name: cifs/rhellxudv01.domain@REALM
 Principal alias: cifs/rhellxudv01.domain@REALM
 Keytab: True

 Principal name: cifs/ipa02.domain@REALM
 Principal alias: cifs/ipa02.domain@REALM
 Keytab: True

 Principal name: nfs/profil01.domain@REALM
 Principal alias: nfs/profil01.domain@REALM
 Keytab: True

 Principal name: cifs/ipa01.domain@REALM
 Principal alias: cifs/ipa01.domain@REALM
 Keytab: True

 Principal name: dogtag/ipa02.domain@REALM
 Principal alias: dogtag/ipa02.domain@REALM
 Keytab: True

 Principal name: dogtag/ipa01.domain@REALM
 Principal alias: dogtag/ipa01.domain@REALM
 Keytab: True

 Principal name: cifs/rhellxudv02.domain@REALM
 Principal alias: cifs/rhellxudv02.domain@REALM
 Keytab: True

 Principal name: HTTP/ipa01.domain@REALM
 Principal alias: HTTP/ipa01.domain@REALM
 Certificate: ..
 ..
 Keytab: True

 -
 Number of entries returned 11
 -

 (some lines truncated.)

 s... somsthing must be disrupting the view in web-ui,

 Tried in Chrome 43 and IE 11

 Looking at what gets requested by the browser at /ipa/session/json I can 
 see in
 the json that it gets the correct content:

 result: {count: 11, result: [,…], summary: "11 services matched", 
 truncated:
 false}
 count: 11
 result: [,…]
 0: {dn:
 "krbprincipalname=cifs/rhellxudv01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 1: {dn:
 "krbprincipalname=dogtag/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 2: {dn:
 "krbprincipalname=nfs/profil01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 3: {dn:
 "krbprincipalname=cifs/rhellxudv02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 4: {dn:
 "krbprincipalname=dogtag/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 5: {dn:
 "krbprincipalname=HTTP/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 6: {dn:
 "krbprincipalname=cifs/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 7: {dn:
 "krbprincipalname=cifs/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 8: {dn:
 "krbprincipalname=ldap/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 9: {dn:
 "krbprincipalname=HTTP/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 10: {dn:
 "krbprincipalname=ldap/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 summary: "11 services matched"
 truncated: false

 So this is obviously only a web-ui problem, but I can't see what causes the
 problem?

 --
 Manage your subscription for the Freeipa-users mailing list:
 https://www.redhat.com/mailman/listinfo/freeipa-users
 Go to http://freeipa.org for more info on the project

> --
> Pavel^3 Vomacka

-- 

Med venlig hilsen 

Troels Hansen 

Systemkonsulent 

Casalogic A/S 

T (+45) 70 20 10 63 

M (+45) 22 43 71 57 

Red Hat

Re: [Freeipa-users] Services missing in web-ui

2016-12-07 Thread Pavel Vomacka

Hello,

it is caused by missing canonical name on services which were created in 
older versions of FreeIPA. Fixed ticket here: 
https://fedorahosted.org/freeipa/ticket/6397 .


On 12/07/2016 11:48 AM, Fujisan wrote:

And with Firefox 50.0.2.

F.

On Wed, Dec 7, 2016 at 11:46 AM, Fujisan > wrote:


I have the same issue with version 4.4.2

$ rpm -qa|grep freeipa
freeipa-server-4.4.2-1.fc25.x86_64
freeipa-python-compat-4.4.2-1.fc25.noarch
freeipa-server-common-4.4.2-1.fc25.noarch
freeipa-common-4.4.2-1.fc25.no
arch
freeipa-server-trust-ad-4.4.2-1.fc25.x86_64
freeipa-client-4.4.2-1.fc25.x86_64
freeipa-client-common-4.4.2-1.fc25.noarch


​F.​


On Wed, Dec 7, 2016 at 11:13 AM, Troels Hansen mailto:t...@casalogic.dk>> wrote:

I have a strange issue in IPA 4.4.0-12 (RHEL 7.3)


Navigating to Identity -> Services reveals 5 services. 2 cifs,
2 dogtag and one empty line...

cifs/host1.domain@REALM
cifs/host2.domain@REALM
dogtag/ipa01.domain@REALM
dogtag/ipa02.domain@REALM



However, from CLI everything looks OK:

# ipa service-find
---
11 services matched
---
Principal name: ldap/ipa02.domain@REALM
Principal alias: ldap/ipa02.domain@REALM
Certificate: ...
...


Keytab: True

Principal name: ldap/ipa01.domain@REALM
Principal alias: ldap/ipa01.domain@REALM
Certificate: ...
...


Keytab: True

Principal name: HTTP/ipa02.domain@REALM
Principal alias: HTTP/ipa02.domain@REALM
Certificate: 
...



Keytab: True

Principal name: cifs/rhellxudv01.domain@REALM
Principal alias: cifs/rhellxudv01.domain@REALM
Keytab: True



Principal name: cifs/ipa02.domain@REALM
Principal alias: cifs/ipa02.domain@REALM
Keytab: True



Principal name: nfs/profil01.domain@REALM
Principal alias: nfs/profil01.domain@REALM
Keytab: True



Principal name: cifs/ipa01.domain@REALM
Principal alias: cifs/ipa01.domain@REALM
Keytab: True

Principal name: dogtag/ipa02.domain@REALM
Principal alias: dogtag/ipa02.domain@REALM
Keytab: True



Principal name: dogtag/ipa01.domain@REALM
Principal alias: dogtag/ipa01.domain@REALM
Keytab: True



Principal name: cifs/rhellxudv02.domain@REALM
Principal alias: cifs/rhellxudv02.domain@REALM
Keytab: True



Principal name: HTTP/ipa01.domain@REALM
Principal alias: HTTP/ipa01.domain@REALM
Certificate: ..
..
Keytab: True



-
Number of entries returned 11
-




(some lines truncated.)


s... somsthing must be disrupting the view in web-ui,


Tried in Chrome 43 and IE 11


Looking at what gets requested by the browser at
/ipa/session/json I can see in the json that it gets the
correct content:


result: {count: 11, result: [,…], summary: "11 services
matched", truncated: false}
count: 11
result: [,…]
0: {dn:

"krbprincipalname=cifs/rhellxudv01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
1: {dn:

"krbprincipalname=dogtag/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
2: {dn:

"krbprincipalname=nfs/profil01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
3: {dn:

"krbprincipalname=cifs/rhellxudv02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
4: {dn:

"krbprincipalname=dogtag/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
5: {dn:

"krbprincipalname=HTTP/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
6: {dn:

"krbprincipalname=cifs/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
7: {dn:

"krbprincipalname=cifs/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
8: {dn:

"krbprincipalname=ldap/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
9: {dn:

"krbprincipalname=HTTP/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
10: {dn:

"krbprincipalname=ldap/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
summary: "11 services matched"
truncated: false



So this is obviously only a web-ui problem, but I can't see
what causes the problem?


--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users

Go to http://fre

Re: [Freeipa-users] Services missing in web-ui

2016-12-07 Thread Fujisan
And with Firefox 50.0.2.

F.

On Wed, Dec 7, 2016 at 11:46 AM, Fujisan  wrote:

> I have the same issue with version 4.4.2
>
> $ rpm -qa|grep freeipa
> freeipa-server-4.4.2-1.fc25.x86_64
> freeipa-python-compat-4.4.2-1.fc25.noarch
> freeipa-server-common-4.4.2-1.fc25.noarch
> freeipa-common-4.4.2-1.fc25.noarch
> freeipa-server-trust-ad-4.4.2-1.fc25.x86_64
> freeipa-client-4.4.2-1.fc25.x86_64
> freeipa-client-common-4.4.2-1.fc25.noarch
>
>
> ​F.​
>
>
> On Wed, Dec 7, 2016 at 11:13 AM, Troels Hansen  wrote:
>
>> I have a strange issue in IPA 4.4.0-12 (RHEL 7.3)
>>
>>
>> Navigating to Identity -> Services reveals 5 services. 2 cifs, 2 dogtag
>> and one empty line...
>>
>> cifs/host1.domain@REALM
>> cifs/host2.domain@REALM
>> dogtag/ipa01.domain@REALM
>> dogtag/ipa02.domain@REALM
>>
>>
>>
>> However, from CLI everything looks OK:
>>
>> # ipa service-find
>> ---
>> 11 services matched
>> ---
>> Principal name: ldap/ipa02.domain@REALM
>> Principal alias: ldap/ipa02.domain@REALM
>> Certificate: ...
>> ...
>>
>>
>> Keytab: True
>>
>> Principal name: ldap/ipa01.domain@REALM
>> Principal alias: ldap/ipa01.domain@REALM
>> Certificate: ...
>> ...
>>
>>
>> Keytab: True
>>
>> Principal name: HTTP/ipa02.domain@REALM
>> Principal alias: HTTP/ipa02.domain@REALM
>> Certificate: 
>> ...
>>
>>
>>
>> Keytab: True
>>
>> Principal name: cifs/rhellxudv01.domain@REALM
>> Principal alias: cifs/rhellxudv01.domain@REALM
>> Keytab: True
>>
>>
>>
>> Principal name: cifs/ipa02.domain@REALM
>> Principal alias: cifs/ipa02.domain@REALM
>> Keytab: True
>>
>>
>>
>> Principal name: nfs/profil01.domain@REALM
>> Principal alias: nfs/profil01.domain@REALM
>> Keytab: True
>>
>>
>>
>> Principal name: cifs/ipa01.domain@REALM
>> Principal alias: cifs/ipa01.domain@REALM
>> Keytab: True
>>
>> Principal name: dogtag/ipa02.domain@REALM
>> Principal alias: dogtag/ipa02.domain@REALM
>> Keytab: True
>>
>>
>>
>> Principal name: dogtag/ipa01.domain@REALM
>> Principal alias: dogtag/ipa01.domain@REALM
>> Keytab: True
>>
>>
>>
>> Principal name: cifs/rhellxudv02.domain@REALM
>> Principal alias: cifs/rhellxudv02.domain@REALM
>> Keytab: True
>>
>>
>>
>> Principal name: HTTP/ipa01.domain@REALM
>> Principal alias: HTTP/ipa01.domain@REALM
>> Certificate: ..
>> ..
>> Keytab: True
>>
>>
>>
>> -
>> Number of entries returned 11
>> -
>>
>>
>>
>>
>> (some lines truncated.)
>>
>>
>> s... somsthing must be disrupting the view in web-ui,
>>
>>
>> Tried in Chrome 43 and IE 11
>>
>>
>> Looking at what gets requested by the browser at /ipa/session/json I can
>> see in the json that it gets the correct content:
>>
>>
>> result: {count: 11, result: [,…], summary: "11 services matched",
>> truncated: false}
>> count: 11
>> result: [,…]
>> 0: {dn: "krbprincipalname=cifs/rhellxudv01.domain@REALM,cn=services,
>> cn=accounts,dc=domain",…}
>> 1: {dn: "krbprincipalname=dogtag/ipa01.domain@REALM,cn=services,cn=a
>> ccounts,dc=domain",…}
>> 2: {dn: "krbprincipalname=nfs/profil01.domain@REALM,cn=services,cn=a
>> ccounts,dc=domain",…}
>> 3: {dn: "krbprincipalname=cifs/rhellxudv02.domain@REALM,cn=services,
>> cn=accounts,dc=domain",…}
>> 4: {dn: "krbprincipalname=dogtag/ipa02.domain@REALM,cn=services,cn=a
>> ccounts,dc=domain",…}
>> 5: {dn: "krbprincipalname=HTTP/ipa01.domain@REALM,cn=services,cn=acc
>> ounts,dc=domain",…}
>> 6: {dn: "krbprincipalname=cifs/ipa02.domain@REALM,cn=services,cn=acc
>> ounts,dc=domain",…}
>> 7: {dn: "krbprincipalname=cifs/ipa01.domain@REALM,cn=services,cn=acc
>> ounts,dc=domain",…}
>> 8: {dn: "krbprincipalname=ldap/ipa01.domain@REALM,cn=services,cn=acc
>> ounts,dc=domain",…}
>> 9: {dn: "krbprincipalname=HTTP/ipa02.domain@REALM,cn=services,cn=acc
>> ounts,dc=domain",…}
>> 10: {dn: "krbprincipalname=ldap/ipa02.domain@REALM,cn=services,cn=acc
>> ounts,dc=domain",…}
>> summary: "11 services matched"
>> truncated: false
>>
>>
>>
>> So this is obviously only a web-ui problem, but I can't see what causes
>> the problem?
>>
>> --
>> Manage your subscription for the Freeipa-users mailing list:
>> https://www.redhat.com/mailman/listinfo/freeipa-users
>> Go to http://freeipa.org for more info on the project
>>
>
>
-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Services missing in web-ui

2016-12-07 Thread Fujisan
I have the same issue with version 4.4.2

$ rpm -qa|grep freeipa
freeipa-server-4.4.2-1.fc25.x86_64
freeipa-python-compat-4.4.2-1.fc25.noarch
freeipa-server-common-4.4.2-1.fc25.noarch
freeipa-common-4.4.2-1.fc25.noarch
freeipa-server-trust-ad-4.4.2-1.fc25.x86_64
freeipa-client-4.4.2-1.fc25.x86_64
freeipa-client-common-4.4.2-1.fc25.noarch


​F.​


On Wed, Dec 7, 2016 at 11:13 AM, Troels Hansen  wrote:

> I have a strange issue in IPA 4.4.0-12 (RHEL 7.3)
>
>
> Navigating to Identity -> Services reveals 5 services. 2 cifs, 2 dogtag
> and one empty line...
>
> cifs/host1.domain@REALM
> cifs/host2.domain@REALM
> dogtag/ipa01.domain@REALM
> dogtag/ipa02.domain@REALM
>
>
>
> However, from CLI everything looks OK:
>
> # ipa service-find
> ---
> 11 services matched
> ---
> Principal name: ldap/ipa02.domain@REALM
> Principal alias: ldap/ipa02.domain@REALM
> Certificate: ...
> ...
>
>
> Keytab: True
>
> Principal name: ldap/ipa01.domain@REALM
> Principal alias: ldap/ipa01.domain@REALM
> Certificate: ...
> ...
>
>
> Keytab: True
>
> Principal name: HTTP/ipa02.domain@REALM
> Principal alias: HTTP/ipa02.domain@REALM
> Certificate: 
> ...
>
>
>
> Keytab: True
>
> Principal name: cifs/rhellxudv01.domain@REALM
> Principal alias: cifs/rhellxudv01.domain@REALM
> Keytab: True
>
>
>
> Principal name: cifs/ipa02.domain@REALM
> Principal alias: cifs/ipa02.domain@REALM
> Keytab: True
>
>
>
> Principal name: nfs/profil01.domain@REALM
> Principal alias: nfs/profil01.domain@REALM
> Keytab: True
>
>
>
> Principal name: cifs/ipa01.domain@REALM
> Principal alias: cifs/ipa01.domain@REALM
> Keytab: True
>
> Principal name: dogtag/ipa02.domain@REALM
> Principal alias: dogtag/ipa02.domain@REALM
> Keytab: True
>
>
>
> Principal name: dogtag/ipa01.domain@REALM
> Principal alias: dogtag/ipa01.domain@REALM
> Keytab: True
>
>
>
> Principal name: cifs/rhellxudv02.domain@REALM
> Principal alias: cifs/rhellxudv02.domain@REALM
> Keytab: True
>
>
>
> Principal name: HTTP/ipa01.domain@REALM
> Principal alias: HTTP/ipa01.domain@REALM
> Certificate: ..
> ..
> Keytab: True
>
>
>
> -
> Number of entries returned 11
> -
>
>
>
>
> (some lines truncated.)
>
>
> s... somsthing must be disrupting the view in web-ui,
>
>
> Tried in Chrome 43 and IE 11
>
>
> Looking at what gets requested by the browser at /ipa/session/json I can
> see in the json that it gets the correct content:
>
>
> result: {count: 11, result: [,…], summary: "11 services matched",
> truncated: false}
> count: 11
> result: [,…]
> 0: {dn: "krbprincipalname=cifs/rhellxudv01.domain@REALM,cn=services,
> cn=accounts,dc=domain",…}
> 1: {dn: "krbprincipalname=dogtag/ipa01.domain@REALM,cn=services,cn=
> accounts,dc=domain",…}
> 2: {dn: "krbprincipalname=nfs/profil01.domain@REALM,cn=services,cn=
> accounts,dc=domain",…}
> 3: {dn: "krbprincipalname=cifs/rhellxudv02.domain@REALM,cn=services,
> cn=accounts,dc=domain",…}
> 4: {dn: "krbprincipalname=dogtag/ipa02.domain@REALM,cn=services,cn=
> accounts,dc=domain",…}
> 5: {dn: "krbprincipalname=HTTP/ipa01.domain@REALM,cn=services,cn=acc
> ounts,dc=domain",…}
> 6: {dn: "krbprincipalname=cifs/ipa02.domain@REALM,cn=services,cn=acc
> ounts,dc=domain",…}
> 7: {dn: "krbprincipalname=cifs/ipa01.domain@REALM,cn=services,cn=acc
> ounts,dc=domain",…}
> 8: {dn: "krbprincipalname=ldap/ipa01.domain@REALM,cn=services,cn=acc
> ounts,dc=domain",…}
> 9: {dn: "krbprincipalname=HTTP/ipa02.domain@REALM,cn=services,cn=acc
> ounts,dc=domain",…}
> 10: {dn: "krbprincipalname=ldap/ipa02.domain@REALM,cn=services,cn=acc
> ounts,dc=domain",…}
> summary: "11 services matched"
> truncated: false
>
>
>
> So this is obviously only a web-ui problem, but I can't see what causes
> the problem?
>
> --
> Manage your subscription for the Freeipa-users mailing list:
> https://www.redhat.com/mailman/listinfo/freeipa-users
> Go to http://freeipa.org for more info on the project
>
-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

[Freeipa-users] Services missing in web-ui

2016-12-07 Thread Troels Hansen


I have a strange issue in IPA 4.4.0-12 (RHEL 7.3) 




Navigating to Identity -> Services reveals 5 services. 2 cifs, 2 dogtag and one 
empty line... 

cifs/host1.domain@REALM 
cifs/host2.domain@REALM 
dogtag/ipa01.domain@REALM 
dogtag/ipa02.domain@REALM 







However, from CLI everything looks OK: 

# ipa service-find 
--- 
11 services matched 
--- 
Principal name: ldap/ipa02.domain@REALM 
Principal alias: ldap/ipa02.domain@REALM 
Certificate: ... 
... 


Keytab: True 

Principal name: ldap/ipa01.domain@REALM 
Principal alias: ldap/ipa01.domain@REALM 
Certificate: ... 
... 


Keytab: True 

Principal name: HTTP/ipa02.domain@REALM 
Principal alias: HTTP/ipa02.domain@REALM 
Certificate:  
... 







Keytab: True 

Principal name: cifs/rhellxudv01.domain@REALM 
Principal alias: cifs/rhellxudv01.domain@REALM 
Keytab: True 





Principal name: cifs/ipa02.domain@REALM 
Principal alias: cifs/ipa02.domain@REALM 
Keytab: True 





Principal name: nfs/profil01.domain@REALM 
Principal alias: nfs/profil01.domain@REALM 
Keytab: True 





Principal name: cifs/ipa01.domain@REALM 
Principal alias: cifs/ipa01.domain@REALM 
Keytab: True 

Principal name: dogtag/ipa02.domain@REALM 
Principal alias: dogtag/ipa02.domain@REALM 
Keytab: True 





Principal name: dogtag/ipa01.domain@REALM 
Principal alias: dogtag/ipa01.domain@REALM 
Keytab: True 





Principal name: cifs/rhellxudv02.domain@REALM 
Principal alias: cifs/rhellxudv02.domain@REALM 
Keytab: True 





Principal name: HTTP/ipa01.domain@REALM 
Principal alias: HTTP/ipa01.domain@REALM 
Certificate: .. 
.. 
Keytab: True 







- 
Number of entries returned 11 
- 










(some lines truncated.) 



s... somsthing must be disrupting the view in web-ui, 


Tried in Chrome 43 and IE 11 




Looking at what gets requested by the browser at /ipa/session/json I can see in 
the json that it gets the correct content: 





result: {count: 11, result: [,…], summary: "11 services matched", truncated: 
false} 
count: 11 
result: [,…] 
0: {dn: 
"krbprincipalname=cifs/rhellxudv01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 
1: {dn: 
"krbprincipalname=dogtag/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 
2: {dn: 
"krbprincipalname=nfs/profil01.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 
3: {dn: 
"krbprincipalname=cifs/rhellxudv02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 
4: {dn: 
"krbprincipalname=dogtag/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…}
 
5: {dn: 
"krbprincipalname=HTTP/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…} 
6: {dn: 
"krbprincipalname=cifs/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…} 
7: {dn: 
"krbprincipalname=cifs/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…} 
8: {dn: 
"krbprincipalname=ldap/ipa01.domain@REALM,cn=services,cn=accounts,dc=domain",…} 
9: {dn: 
"krbprincipalname=HTTP/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…} 
10: {dn: 
"krbprincipalname=ldap/ipa02.domain@REALM,cn=services,cn=accounts,dc=domain",…} 
summary: "11 services matched" 
truncated: false 







So this is obviously only a web-ui problem, but I can't see what causes the 
problem? 
-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project