[Freeipa-devel] [PATCH 0006] Start dirsrv for kdcproxy upgrade

Christian Heimes cheimes at redhat.com
Fri Jul 10 16:29:00 UTC 2015


Hi,

this patch ensures that DS is running before HTTPInstance attempts to
connect to LDAP.

https://fedorahosted.org/freeipa/ticket/5113


While I was testing the patch I ran into trouble with DS. The upgrade
script couldn't connect to 389/TCP, although ns-slapd was running. After
some digging I found this log line:

Jul 10 18:13:24 vm-120.abc.idm.lab.eng.brq.redhat.com ns-slapd[6278]:
[10/Jul/2015:18:13:24 +0200] - Information: Non-Secure Port Disabled

which eventually lead me to /etc/dirsrv/slapd-IPA-EXAMPLE/dse.ldif. The
port was disabled with "nsslapd-port: 0". After I stopped DS, changed
the port back to 389 and started DS again, ipa-server-upgrade worked again.

Christian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-cheimes-0006-Start-dirsrv-for-kdcproxy-upgrade.patch
Type: text/x-patch
Size: 2424 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20150710/00eb48a8/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 455 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20150710/00eb48a8/attachment.sig>


More information about the Freeipa-devel mailing list