May be you should specify the specific $SUFFIX according to your environment.<br><br><div><sign signid="0"><div style="color:#909090;font-family:Arial Narrow;font-size:12px"><br><br><br><br>------------------</div><div style="font-size:14px;font-family:Verdana;color:#000;">祝:<br>    工作顺利!生活愉快!<br><span style="text-decoration: underline;"></span>--------------------------<br>长沙研发中心 郑磊 <br>Phone:18684703229<br>Email:zhenglei@kylinos.cn<br>Company:天津麒麟信息技术有限公司<br>Address:湖南长沙市开福区三一大道工美大厦十四楼<br>
</div></sign></div><div> </div><div><includetail><div> </div><div> </div><div style="font:Verdana normal 14px;color:#000;"><div style="FONT-SIZE: 12px;FONT-FAMILY: Arial Narrow;padding:2px 0 2px 0;">------------------ Original ------------------</div><div style="FONT-SIZE: 12px;background:#efefef;padding:8px;"><div id="menu_sender"><b>From: </b> "Matt ."<yamakasi.014@gmail.com>;</div><div><b>Date: </b> Tue, Oct 18, 2016 06:30 AM</div><div><b>To: </b> "freeipa-users@redhat.com"<freeipa-users@redhat.com>; <wbr></div><div></div><div><b>Subject: </b> [Freeipa-users] Upgrade 4.4.2-1.fc24 security library failure.</div></div><div> </div>Hi Guys,<br><br>I'm having a failure on my upgrade for 4.4.2-1 on Fedora 24<br><br>I already checked some info and:<br><br>ldapsearch -Y GSSAPI -b cn=CAcert,cn=ipa,cn=etc,$SUFFIX<br><br>Gives me TU instead of MII as expected.<br><br>Any suggestions further ?<br><br>Thanks,<br><br>Matt<br><br><br>2016-10-17T22:19:10Z DEBUG Starting external process<br>2016-10-17T22:19:10Z DEBUG args=/usr/bin/certutil -d<br>/etc/dirsrv/slapd-MY-REALM -L -n Server-Cert -a<br>2016-10-17T22:19:10Z DEBUG Process finished, return code=255<br>2016-10-17T22:19:10Z DEBUG stdout=<br>2016-10-17T22:19:10Z DEBUG stderr=certutil: Could not find cert: Server-Cert<br>: PR_FILE_NOT_FOUND_ERROR: File not found<br><br>2016-10-17T22:19:10Z ERROR IPA server upgrade failed: Inspect<br>/var/log/ipaupgrade.log and run command ipa-server-upgrade manually.<br>2016-10-17T22:19:11Z DEBUG   File<br>"/usr/lib/python2.7/site-packages/ipapython/admintool.py", line 172,<br>in execute<br>    return_value = self.run()<br>  File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_upgrade.py",<br>line 46, in run<br>    server.upgrade()<br>  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/upgrade.py",<br>line 1867, in upgrade<br>    upgrade_configuration()<br>  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/upgrade.py",<br>line 1770, in upgrade_configuration<br>    certificate_renewal_update(ca, ds, http),<br>  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/upgrade.py",<br>line 1027, in certificate_renewal_update<br>    ds.start_tracking_certificates(serverid)<br>  File "/usr/lib/python2.7/site-packages/ipaserver/install/dsinstance.py",<br>line 996, in start_tracking_certificates<br>    'restart_dirsrv %s' % serverid)<br>  File "/usr/lib/python2.7/site-packages/ipaserver/install/certs.py",<br>line 307, in track_server_cert<br>    nsscert = x509.load_certificate(cert, dbdir=self.secdir)<br>  File "/usr/lib/python2.7/site-packages/ipalib/x509.py", line 129, in<br>load_certificate<br>    return nss.Certificate(buffer(data))  # pylint: disable=buffer-builtin<br><br><br>016-10-17T22:19:11Z DEBUG The ipa-server-upgrade command failed,<br>exception: NSPRError: (SEC_ERROR_LIBRARY_FAILURE)<br>security library failure.<br>2016-10-17T22:19:11Z ERROR Unexpected error - see<br>/var/log/ipaupgrade.log for details:<br>NSPRError: (SEC_ERROR_LIBRARY_FAILURE) security library failure.<br>2016-10-17T22:19:11Z ERROR The ipa-server-upgrade command failed. See<br>/var/log/ipaupgrade.log for more information<br><br>-- <br>Manage your subscription for the Freeipa-users mailing list:<br>https://www.redhat.com/mailman/listinfo/freeipa-users<br>Go to http://freeipa.org for more info on the project</div><!--<![endif]--></includetail></div>