[Freeipa-users] ipa-ods-exporter failed ?
Günther J. Niederwimmer
gjn at gjn.priv.at
Sat Jun 18 13:03:42 UTC 2016
hello,
Am Freitag, 17. Juni 2016, 23:05:32 CEST schrieb Martin Basti:
> On 17.06.2016 18:29, Günther J. Niederwimmer wrote:
> > Hello,
> >
> > Am Freitag, 17. Juni 2016, 14:13:55 CEST schrieb Martin Basti:
> >> On 17.06.2016 12:54, Günther J. Niederwimmer wrote:
> >>> Hello List,
> >>>
> >>> Am Freitag, 17. Juni 2016, 07:51:45 CEST schrieb Petr Spacek:
> >>>> On 16.6.2016 21:51, Lukas Slebodnik wrote:
> >>>>> On (16/06/16 11:54), Günther J. Niederwimmer wrote:
> >>>>>> Hello
> >>>>>>
> >>>>>> on my system the ods-exporter i mean have a problem.
> >>>>>>
> >>>>>> I have this in the logs
> >>>>>> CentOS 7.(2) ipa 4.3.1
> >>>>>>
> >>>>>> Jun 16 11:38:28 ipa ipa-ods-exporter: raise
> >>>>>> errors.ACIError(info=info)
> >>>>>> Jun 16 11:38:28 ipa ipa-ods-exporter: ipalib.errors.ACIError:
> >>>>>> Insufficient
> >>>>>> access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS
> >>>>>> failure.
> >>>>>> Minor code may provide more information (Ticket expired)
> >>>>>>
> >>>>> ^^^^^^^^^^^^^^
> >>>>>
> >>>>> Here seems to be a reason why it failed.
> >>>>> But I can't help you more.
> >>>>
> >>>> Lukas is right. Interesting, this should never happen :-)
> >>>
> >>> this have I also found ;-)
> >>>
> >>>> Please enable debugging using procedure
> >>>> http://www.freeipa.org/page/Troubleshooting#ipa_command_crashes_or_retu
> >>>> rn
> >>>> s_n o_data and check logs after next ipa-ods-exporter restart.
> >>>> Thank you!
> >>>
> >>> OK,
> >>>
> >>> I attache the messages log?
> >>>
> >>> I mean this is a problem with my DNS ?
> >>
> >> Hello,
> >> can you check kerberos status of ipa-ods-exporter service in webUI?
> >>
> >> identity/services/ipa-ods-exported/<hostname>
> >> There should be kerberos status in right top corner in details view
> >
> > I have a
> > identity/services/ipa-ods-exporter/..
> >
> > with a "Kerberos Key Present, Service Provisioned"
> >
> > but no Certificate ?
>
> Can you try,
>
> # kinit -kt /etc/ipa/dnssec/ipa-ods-exporter.keytab
> ipa-ods-exporter/$(hostname)
OK
I can do a "kinit -kt /etc/ipa/dnssec/ipa-ods-exporter.keytab ipa-ods-
exporter/$(hostname)"
written on one line!! is this OK.
> and do ldapsearch
> # ldapsearch -Y GSSAPI
and also ldapsearch is OK
> It should show us if keytab is okay
But the Error is present :-(.
> Certificate is not needed.
OK
Thanks for the Help.
--
mit freundlichen Grüßen / best regards,
Günther J. Niederwimmer
More information about the Freeipa-users
mailing list