[Freeipa-users] FreeIpa 3.0.1 installation on Fedora 18
Dmitri Pal
dpal at redhat.com
Thu Dec 6 23:57:10 UTC 2012
On 12/06/2012 12:44 PM, Maciej Sawicki wrote:
> On Thu, Dec 6, 2012 at 5:57 PM, John Dennis <jdennis at redhat.com> wrote:
>> Yes, that's right, reboot twice! (Apparently that's needed to get systemd
>> updates installed and working)
>>
> unfortunately it didn't help.
>
> the strange thing is that during first try (remove freeipa-server
> packege, reboot, reboot, install free-ipaserver, reboot, reboot, run
> ipa-server-install) i get one more error:
>
>
> Configuring directory server for the CA (pkids): Estimated time 30 seconds
> [1/3]: creating directory server user
> [2/3]: creating directory server instance
> ipa : CRITICAL failed to create ds instance Command
> '/usr/sbin/setup-ds.pl --silent --logfile - -f /tmp/tmpWS7pd0'
> returned non-zero exit status 1
> [3/3]: restarting directory server
> ipa : CRITICAL Failed to restart the directory server. See the
> installation log for details.
> Done configuring directory server for the CA (pkids).
> Configuring certificate server (pki-tomcatd): Estimated time 3 minutes
> 30 seconds
> [1/19]: creating certificate server user
> [2/19]: configuring certificate server instance
> ipa : CRITICAL failed to configure ca instance Command
> '/usr/sbin/pkispawn -s CA -f /tmp/tmpTf7vHu' returned non-zero exit
> status 1
>
> and log:
>
> ###############################################################################
> ## 'TPS' Data: ##
> ## ##
> ## Values in this section are common to PKI TPS subsystems, and contain ##
> ## required information which MAY be overridden by users as necessary. ##
> ###############################################################################
> [TPS]
> pki_subsystem=TPS
> pki_subsystem_name=
>
> 2012-12-06T17:40:27Z DEBUG Starting external process
> 2012-12-06T17:40:27Z DEBUG args=/usr/sbin/pkispawn -s CA -f /tmp/tmpTf7vHu
> 2012-12-06T17:40:31Z DEBUG Process finished, return code=1
> 2012-12-06T17:40:31Z DEBUG stdout=
> 2012-12-06T17:40:31Z DEBUG stderr=Traceback (most recent call last):
> File "/usr/sbin/pkispawn", line 223, in <module>
> main(sys.argv)
> File "/usr/sbin/pkispawn", line 207, in main
> fromlist = [pki_scriptlet[4:]])
> File "/usr/lib/python2.7/site-packages/pki/deployment/initialization.py",
> line 25, in <module>
> import pkihelper as util
> File "/usr/lib/python2.7/site-packages/pki/deployment/pkihelper.py",
> line 39, in <module>
> import seobject
> File "/usr/lib64/python2.7/site-packages/seobject.py", line 27, in <module>
> import sepolicy
> File "/usr/lib64/python2.7/site-packages/sepolicy/__init__.py", line
> 43, in <module>
> policy(policy_file)
> File "/usr/lib64/python2.7/site-packages/sepolicy/__init__.py", line
> 40, in policy
> _policy.policy(policy_file)
> RuntimeError: Cannot allocate memory
>
> 2012-12-06T17:40:31Z CRITICAL failed to configure ca instance Command
> '/usr/sbin/pkispawn -s CA -f /tmp/tmpTf7vHu' returned non-zero exit
> status 1
> 2012-12-06T17:40:31Z INFO File
> "/usr/lib/python2.7/site-packages/ipaserver/install/installutils.py",
> line 614, in run_script
> return_value = main_function()
>
> File "/sbin/ipa-server-install", line 943, in main
> subject_base=options.subject)
>
> File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py",
> line 591, in configure_instance
> self.start_creation(runtime=210)
>
> File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py",
> line 358, in start_creation
> method()
>
> File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py",
> line 695, in __spawn_instance
> raise RuntimeError('Configuration of CA failed')
>
> 2012-12-06T17:40:31Z INFO The ipa-server-install command failed,
> exception: RuntimeError: Configuration of CA failed
>
> but after: ipa-server-install --uninstall, ipa-server-install i get
> only second error:
> [2/19]: configuring certificate server instance
> ipa : CRITICAL failed to configure ca instance Command
> '/usr/sbin/pkispawn -s CA -f /tmp/tmpTf7vHu' returned non-zero exit
> status 1
>
> regards,
> Maciek Sawicki
>
> _______________________________________________
> Freeipa-users mailing list
> Freeipa-users at redhat.com
> https://www.redhat.com/mailman/listinfo/freeipa-users
Do you have SELinux enabled?
Any AVCs?
--
Thank you,
Dmitri Pal
Sr. Engineering Manager for IdM portfolio
Red Hat Inc.
-------------------------------
Looking to carve out IT costs?
www.redhat.com/carveoutcosts/
More information about the Freeipa-users
mailing list