[Freeipa-users] Trouble creating replica

Rob Crittenden rcritten at redhat.com
Tue Feb 19 18:26:58 UTC 2013


Natxo Asenjo wrote:
> On Tue, Feb 19, 2013 at 5:58 PM, Bret Wortman
> <bret.wortman at damascusgrp.com <mailto:bret.wortman at damascusgrp.com>> wrote:
>
>     Digging a bit deeper, I found this in /var/log/pki-ca/catalina.out:
>
>     :
>     Could not connect to LDAP server host oldmaster.my.com
>     <http://oldmaster.my.com> port 7389 Error
>     netscape.ldap.LDAPException: failed to connect to server
>     ldap://oldmaster.my.com:7389 <http://oldmaster.my.com:7389> (91)
>
>     This certainly appears to be a problem, but everyone's
>     authenticating against oldmaster just fine. Thoughts, anyone?
>
>
> can you connect to that port (7389) on oldmaster.my.com
> <http://oldmaster.my.com> from the other replica? (try telnetting to the
> port: telnet oldmaster.my.com <http://oldmaster.my.com> 7389)

7389 is port in the 389-ds instance used by dogtag. Is the instance 
running on oldmaster?

It isn't used for authentication which is why you aren't seeing problems 
with clients.

rob




More information about the Freeipa-users mailing list