[Freeipa-users] Re: Error starting FreeIPA service after update

2021-11-15 Thread Arjen Heidinga via FreeIPA-users
Moring, We saw the exact same thing. Yesterdaymorning (on a sundaymorning) two-thirds of our IPA servers were in limbo. I had the on-duty engineer undo the (automagic)updates. Is it sufficient to update and remove the section? Kind regards, Arjen Heidinga On 14-11-2021 17:34, Pascal Pascher

[Freeipa-users] ipa-replica-install failure.

2021-03-02 Thread Arjen Heidinga via FreeIPA-users
Hi! My primary IPA-server is severely damaged. It is an old server, updated and updated and updated through time (anaconda-ks.cfg is 4 Dec 2014). I run Fedora-33 (now). Because the installation is broken on several parts (missing certs, odd tomcat issues), I thought, lets replicate and reinstall

[Freeipa-users] pki-tomcat wont start; LDAP auth failure

2020-10-08 Thread Arjen Heidinga via FreeIPA-users
Hello all! Since sime time my pki-tomcat deamon can't connect to the LDAP., ging me an error (below). The root-CA was expired in the meantime, I fixed it with some hack-n-slashwork. I am not sure what credentials (none, client cert?) are used to connect. Does anyone have pointers? Hope I

[Freeipa-users] DNSSec renewal issue

2020-03-13 Thread Arjen Heidinga via FreeIPA-users
Hello all! I saw my logs, and notices a stacktrace. I have looked thourouhgly, but I have no clue what goes on. It repeats every minute. It appears there is no problem with my zone. Any clues? Regards, Arjen Mar 13 21:54:14 starkey python3[313742]: detected unhandled Python exception

[Freeipa-users] Re: ipa-replica-install error - no-such-object ldap

2019-01-31 Thread Arjen Heidinga via FreeIPA-users
Op 29-01-19 om 10:28 schreef Florence Blanc-Renaud: > On 1/21/19 4:46 PM, Arjen Heidinga via FreeIPA-users wrote: >> 2019-01-21T13:17:51Z DEBUG Created connection >> context.ldap2_139654961964256 >> 2019-01-21T13:17:52Z DEBUG Fetching nsDS5ReplicaId from master >> [at

[Freeipa-users] ipa-replica-install error - no-such-object ldap

2019-01-21 Thread Arjen Heidinga via FreeIPA-users
Dear all, Perhaps someone could shed some light on what is amiss here. I am trying to install a IPA replica to an ancient freeipa server, which has always run standalone. I have attached the logs for you to read. It seems there is missing something in de ldap tree. Server and replica-to-be are

[Freeipa-users] Re: dnskeysync stacktrace

2018-12-20 Thread Arjen Heidinga via FreeIPA-users
All, Apologies for the subject. It translates to 'Encrypted Message'. Something went wrong with saving to Concepts and other lame excuses. Arjen Op 20-12-18 om 21:53 schreef Arjen Heidinga via FreeIPA-users: > All, > > I am here again bothering with my seemingly borked ins

[Freeipa-users] Versleuteld bericht

2018-12-20 Thread Arjen Heidinga via FreeIPA-users
All, I am here again bothering with my seemingly borked installation. The upgrade from 7.0 to 7.2 on fedora 28-29 finished (finaly), when I spotted in my journal a stacktrace. Digging into it, this appears to be the cause. all I find in the internet are ancient (solved) bugs... It appears that

[Freeipa-users] Re: Trouble with pki-tomcat

2018-12-20 Thread Arjen Heidinga via FreeIPA-users
rwxrwxrwx. 1 root    root  25 Dec 20 14:12 webapps -> /usr/share/pki/ca/webapps Kind Regards, Arjen Heidinga Op 14-12-18 om 15:52 schreef Arjen Heidinga via FreeIPA-users: > Dear all, > > I fear somehow my freeipa server is broken. Perhaps it is time to create > a new one, howe

[Freeipa-users] Trouble with pki-tomcat

2018-12-14 Thread Arjen Heidinga via FreeIPA-users
Dear all, I fear somehow my freeipa server is broken. Perhaps it is time to create a new one, however that would be very time-consuming. Yesterday everything broke, after FreeIPA was upgraded. It is worth mentioning that I had certificate issues recently. My root-CA, and httpd-cert expired.