[Freeipa-users] ipa-ods-exporter failed ?

Petr Spacek pspacek at redhat.com
Mon Jun 20 07:54:11 UTC 2016


On 18.6.2016 15:03, Günther J. Niederwimmer wrote:
> hello,
> 
> Am Freitag, 17. Juni 2016, 23:05:32 CEST schrieb Martin Basti:
>> On 17.06.2016 18:29, Günther J. Niederwimmer wrote:
>>> Hello,
>>>
>>> Am Freitag, 17. Juni 2016, 14:13:55 CEST schrieb Martin Basti:
>>>> On 17.06.2016 12:54, Günther J. Niederwimmer wrote:
>>>>> Hello List,
>>>>>
>>>>> Am Freitag, 17. Juni 2016, 07:51:45 CEST schrieb Petr Spacek:
>>>>>> On 16.6.2016 21:51, Lukas Slebodnik wrote:
>>>>>>> On (16/06/16 11:54), Günther J. Niederwimmer wrote:
>>>>>>>> Hello
>>>>>>>>
>>>>>>>> on my system the ods-exporter i mean have a problem.
>>>>>>>>
>>>>>>>> I have this in the logs
>>>>>>>> CentOS 7.(2) ipa 4.3.1
>>>>>>>>
>>>>>>>> Jun 16 11:38:28 ipa ipa-ods-exporter: raise
>>>>>>>> errors.ACIError(info=info)
>>>>>>>> Jun 16 11:38:28 ipa ipa-ods-exporter: ipalib.errors.ACIError:
>>>>>>>> Insufficient
>>>>>>>> access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS
>>>>>>>> failure.
>>>>>>>> Minor code may provide more information (Ticket expired)
>>>>>>>>
>>>>>>>                                             ^^^^^^^^^^^^^^
>>>>>>>                      
>>>>>>>                      Here seems to be a reason why it failed.
>>>>>>>                      But I can't help you more.
>>>>>>
>>>>>> Lukas is right. Interesting, this should never happen :-)
>>>>>
>>>>> this have I also found ;-)
>>>>>
>>>>>> Please enable debugging using procedure
>>>>>> http://www.freeipa.org/page/Troubleshooting#ipa_command_crashes_or_retu
>>>>>> rn
>>>>>> s_n o_data and check logs after next ipa-ods-exporter restart.
>>>>>> Thank you!
>>>>>
>>>>> OK,
>>>>>
>>>>> I attache the messages log?
>>>>>
>>>>> I mean this is a problem with my DNS ?
>>>>
>>>> Hello,
>>>> can you check kerberos status of ipa-ods-exporter service in webUI?
>>>>
>>>> identity/services/ipa-ods-exported/<hostname>
>>>> There should be kerberos status in right top corner in details view
>>>
>>> I have a
>>> identity/services/ipa-ods-exporter/..
>>>
>>> with a "Kerberos Key Present, Service Provisioned"
>>>
>>> but no Certificate ?
>>
>> Can you try,
>>
>> # kinit -kt /etc/ipa/dnssec/ipa-ods-exporter.keytab
>> ipa-ods-exporter/$(hostname)
> 
> OK
> I can do a "kinit -kt /etc/ipa/dnssec/ipa-ods-exporter.keytab ipa-ods-
> exporter/$(hostname)" 
> 
> written on one line!! is this OK.
> 
>  
>> and do ldapsearch
>> # ldapsearch -Y GSSAPI
> 
> and also ldapsearch is OK
> 
>> It should show us if keytab is okay
> 
> But the Error is present :-(.

We need to see precise error. Please copy&paste it into the e-mail.

It would be awesome if you could follow general rules for bug reporting:
http://www.chiark.greenend.org.uk/~sgtatham/bugs-de.html

Besides other things it would allow us to help you in shorter time.

Have a nice day!

-- 
Petr^2 Spacek




More information about the Freeipa-users mailing list