[Freeipa-users] ipa-ods-exporter failed ?

Martin Basti mbasti at redhat.com
Fri Jun 17 21:05:32 UTC 2016



On 17.06.2016 18:29, Günther J. Niederwimmer wrote:
> Hello,
>
> Am Freitag, 17. Juni 2016, 14:13:55 CEST schrieb Martin Basti:
>> On 17.06.2016 12:54, Günther J. Niederwimmer wrote:
>>> Hello List,
>>>
>>> Am Freitag, 17. Juni 2016, 07:51:45 CEST schrieb Petr Spacek:
>>>> On 16.6.2016 21:51, Lukas Slebodnik wrote:
>>>>> On (16/06/16 11:54), Günther J. Niederwimmer wrote:
>>>>>> Hello
>>>>>>
>>>>>> on my system the ods-exporter i mean have a problem.
>>>>>>
>>>>>> I have this in the logs
>>>>>> CentOS 7.(2) ipa 4.3.1
>>>>>>
>>>>>> Jun 16 11:38:28 ipa ipa-ods-exporter: raise errors.ACIError(info=info)
>>>>>> Jun 16 11:38:28 ipa ipa-ods-exporter: ipalib.errors.ACIError:
>>>>>> Insufficient
>>>>>> access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS
>>>>>> failure.
>>>>>> Minor code may provide more information (Ticket expired)
>>>>>>
>>>>>                                             ^^^^^^^^^^^^^^
>>>>>                      
>>>>>                      Here seems to be a reason why it failed.
>>>>>                      But I can't help you more.
>>>> Lukas is right. Interesting, this should never happen :-)
>>> this have I also found ;-)
>>>
>>>> Please enable debugging using procedure
>>>> http://www.freeipa.org/page/Troubleshooting#ipa_command_crashes_or_return
>>>> s_n o_data and check logs after next ipa-ods-exporter restart.
>>>> Thank you!
>>> OK,
>>>
>>> I attache the messages log?
>>>
>>> I mean this is a problem with my DNS ?
>> Hello,
>> can you check kerberos status of ipa-ods-exporter service in webUI?
>>
>> identity/services/ipa-ods-exported/<hostname>
>> There should be kerberos status in right top corner in details view
>>
> I have a
> identity/services/ipa-ods-exporter/..
>
> with a "Kerberos Key Present, Service Provisioned"
>
> but no Certificate ?
>
>
>

Can you try,

# kinit -kt /etc/ipa/dnssec/ipa-ods-exporter.keytab 
ipa-ods-exporter/$(hostname)

and do ldapsearch
# ldapsearch -Y GSSAPI

It should show us if keytab is okay

Certificate is not needed.




More information about the Freeipa-users mailing list