<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<font size="-1">Hi all,<br>
<br>
So I have 2 Centos7 hosts, with same sssd and nsswitch configs.<br>
One does find the users in IPA, and the other doesn't.<br>
Looks like the Data Provider is offline.<br>
I sent the SIGUSR2 signal to sssd which is supposed to bring him
online. Didn't help.<br>
The hosts can resolve the IPA server hostname. SElinux is
enforced. Iptables is disabled.<br>
<br>
here's my sssd.conf<br>
<br>
[domain/vgt.vito.be]<br>
cache_credentials = True<br>
krb5_store_password_if_offline = True<br>
ipa_domain = vgt.vito.be<br>
id_provider = ipa<br>
auth_provider = ipa<br>
access_provider = ipa<br>
ipa_hostname = epoddev8.vgt.vito.be<br>
chpass_provider = ipa<br>
ipa_server = _srv_, epoddev5.vgt.vito.be<br>
ldap_tls_cacert = /etc/ipa/ca.crt<br>
debug_level = 7<br>
[sssd]<br>
services = nss, sudo, pam, ssh<br>
domains = vgt.vito.be<br>
[nss]<br>
homedir_substring = /home<br>
debug_level = 7<br>
[pam]<br>
[sudo]<br>
[autofs]<br>
[ssh]<br>
[pac]<br>
[ifp]<br>
<br>
<br>
here's the log of sssd_nss.log<br>
<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [accept_fd_handler]
(0x0400): Client connected!<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [sss_cmd_get_version]
(0x0200): Received client version [1].<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [sss_cmd_get_version]
(0x0200): Offered version [1].<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [nss_cmd_getbynam]
(0x0400): Running command [17][SSS_NSS_GETPWNAM] with input
[vdbornem].<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]]
[sss_parse_name_for_domains] (0x0200): name 'vdbornem' matched
without domain, user is vdbornem<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [nss_cmd_getbynam]
(0x0100): Requesting info for [vdbornem] from [<ALL>]<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [nss_cmd_getpwnam_search]
(0x0100): Requesting info for [<a class="moz-txt-link-abbreviated" href="mailto:vdbornem@vgt.vito.be">vdbornem@vgt.vito.be</a>]<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [get_dp_name_and_id]
(0x0400): Not a LOCAL view, continuing with provided values.<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [sss_dp_issue_request]
(0x0400): Issuing request for
[<a class="moz-txt-link-abbreviated" href="mailto:0x7f7ffd1d1880:1:vdbornem@vgt.vito.be@vgt.vito.be">0x7f7ffd1d1880:1:vdbornem@vgt.vito.be@vgt.vito.be</a>]<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [sss_dp_get_account_msg]
(0x0400): Creating request for
[vgt.vito.be][0x1][BE_REQ_USER][1][<a class="moz-txt-link-abbreviated" href="mailto:name=vdbornem@vgt.vito.be">name=vdbornem@vgt.vito.be</a>:-]<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [sss_dp_internal_get_send]
(0x0400): Entering request
[<a class="moz-txt-link-abbreviated" href="mailto:0x7f7ffd1d1880:1:vdbornem@vgt.vito.be@vgt.vito.be">0x7f7ffd1d1880:1:vdbornem@vgt.vito.be@vgt.vito.be</a>]<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [sss_dp_get_reply]
(0x0010): The Data Provider returned an error
[org.freedesktop.sssd.Error.DataProvider.Offline]<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [nss_cmd_getby_dp_callback]
(0x0040): Unable to get information from Data Provider<br>
Error: 3, 5, Failed to get reply from Data Provider<br>
Will try to return what we have in cache<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [sss_dp_req_destructor]
(0x0400): Deleting request:
[<a class="moz-txt-link-abbreviated" href="mailto:0x7f7ffd1d1880:1:vdbornem@vgt.vito.be@vgt.vito.be">0x7f7ffd1d1880:1:vdbornem@vgt.vito.be@vgt.vito.be</a>]<br>
(Wed Mar 22 16:27:22 2017) [sssd[nss]] [client_recv] (0x0200):
Client disconnected!<br>
<br>
Any ideas appreciated.<br>
<br>
Thank you,<br>
<br>
Cheers,<br>
<br>
m.<br>
<br>
</font>
<div class="moz-signature"><br>
--
<br>
<b>Michaël Van de Borne</b><br>
Free Bird Computing SPRL - Gérant<br>
104 rue d'Azebois, 6230 Thiméon<br>
<b>Tel:</b> +32(0)472 695716<br>
<b>Skype:</b> mikemowgli<br>
<b>TVA:</b> BE0637.834.386<br>
<a
href="https://www.linkedin.com/in/micha%C3%ABl-van-de-borne-56409167">Linkedin
profile</a>
<br>
<br>
</div>
</body>
</html>