Hi,

On Thu, Mar 14, 2024 at 9:50 PM D S via FreeIPA-users <
freeipa-users@lists.fedorahosted.org> wrote:

> I added more log info below and also applied this solution to generate
> SIDs https://access.redhat.com/solutions/7052703
> Still unable to login via web UI and every ipa command fails.
>
Did I get it right that the login and commands fail on the replica but
everything is working on the master? If that's the case, check on the
master if the users contain an ipantsecurityidentifier. The users are
replicated and should have the same content on master and replica. You can
also check directly in LDAP (either on the master or the replica), for
instance for the admin user:
ldapsearch -D "cn=directory manager" -W -b
uid=admin,cn=users,cn=accounts,dc=example,dc=com ipantsecurityidentifier

flo

--
> _______________________________________________
> FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
> To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
> Do not reply to spam, report it:
> https://pagure.io/fedora-infrastructure/new_issue
>
--
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to