<table cellspacing="0" cellpadding="0" border="0" ><tr><td valign="top" style="font: inherit;">Hi,<div><br></div><div>Further to the ongoing deployment of Linux clients and servers using FreeIPA, I was able to successfully get all the requirements like,</div><div><br></div><div> -- complete centralized authentication and administration </div><div> -- NFS home share</div><div> -- HBAC</div><div> -- FreeIPA acting as Integrated DNS server</div><div><br></div><div>Everything was good during the testing period. But when we went to production since day before yesterday, we are facing a serious issue. The DNS in IPA is giving out some problems. All of a sudden it becomes unresponsive. We already noticed this twice in the past 48 hours. Since this is the name server for the entire network, everything depending on this for name resolution fails. When I log in to FreeIPA server machine and tries to see the status of named service(service
named status) the command hangs. Then I need to forcefully kill the named service and start it again(or alternatively restart ipa service) to get everything back to normal. I checked all the relevant log files and could see the following at various point of time in the /var/log/messages(trimmed out most of the part to show only possible named/sssd/ipa errors)</div><div><br></div><div><div>Jul 22 05:57:55 openipa named[10135]: semaphore.c:70: fatal error:</div><div>Jul 22 05:57:55 openipa named[10135]: RUNTIME_CHECK(((pthread_mutex_destroy((&sem->mutex)) == 0) ? 0 : 34) == 0) failed</div><div>Jul 22 05:57:55 openipa named[10135]: exiting (due to fatal error in library)</div><div>Jul 22 05:57:55 openipa abrt[12698]: /var/named/core.10135 is not a regular file with link count 1: Permission denied</div></div><div><br></div><div><br></div><div><div>Jul 22 14:35:56 openipa [sssd[ldap_child[17070]]]: Failed to initialize credentials using keytab
[(null)]: Decrypt integrity check failed. Unable to create GSSAPI-encrypted LDAP connection.</div><div>Jul 22 14:35:56 openipa [sssd[ldap_child[17072]]]: Failed to initialize credentials using keytab [(null)]: Decrypt integrity check failed. Unable to create GSSAPI-encrypted LDAP connection.</div></div><div><br></div><div><br></div><div><div>Jul 22 17:54:33 openipa named[15678]: error (network unreachable) resolving 'snapfiles.com/AAAA/IN': 2001:503:231d::2:30#53</div></div><div><br></div><div><div><br></div><div>Jul 22 20:00:02 openipa python: IPA compliance checking failed: Error initializing principal host/openipa.hugayet.com@HUGAYET.COM in /etc/krb5.keytab: (-1765328353, 'Decrypt integrity check failed')</div></div><div><br></div><div><br></div><div><div><div>Jul 23 09:10:01 openipa abrt[21599]: saved core dump of pid 20934 (/usr/sbin/named) to /var/spool/abrt/ccpp-1311401401-20934.new/coredump (37900288 bytes)</div><div>Jul 23 09:10:01 openipa
abrtd: Directory 'ccpp-1311401401-20934' creation detected</div><div>Jul 23 09:10:01 openipa abrtd: Crash is in database already (dup of /var/spool/abrt/ccpp-1307530903-2297)</div><div>Jul 23 09:10:01 openipa abrtd: Deleting crash ccpp-1311401401-20934 (dup of ccpp-1307530903-2297), sending dbus signal</div><div>Jul 23 09:10:03 openipa named[21631]: starting BIND 9.7.3-RedHat-9.7.3-2.el6 -u named -4</div></div><div><br></div><div><br></div><div>Jul 23 15:35:56 openipa [sssd[ldap_child[22297]]]: Failed to initialize credentials using keytab [(null)]: Decrypt integrity check failed. Unable to create GSSAPI-encrypted LDAP connection.</div><div>Jul 23 15:35:56 openipa [sssd[ldap_child[22298]]]: Failed to initialize credentials using keytab [(null)]: Decrypt integrity check failed. Unable to create GSSAPI-encrypted LDAP connection.</div></div><div><br></div><div><div>Jul 23 09:10:03 openipa named[21631]: adjusted limit on open files from 1024 to
1048576</div></div><div><br></div><div><div><br></div><div>Jul 24 03:16:01 openipa [sssd[ldap_child[22964]]]: Failed to initialize credentials using keytab [(null)]: Decrypt integrity check failed. Unable to create GSSAPI-encrypted LDAP connection.</div><div>Jul 24 04:00:02 openipa python: IPA compliance checking failed: Error initializing principal host/openipa.hugayet.com@HUGAYET.COM in /etc/krb5.keytab: (-1765328353, 'Decrypt integrity check failed')</div><div>Jul 24 06:17:25 openipa named[21631]: semaphore.c:70: fatal error:</div><div>Jul 24 06:17:25 openipa named[21631]: RUNTIME_CHECK(((pthread_mutex_destroy((&sem->mutex)) == 0) ? 0 : 34) == 0) failed</div><div>Jul 24 06:17:25 openipa named[21631]: exiting (due to fatal error in library)</div><div>Jul 24 06:17:25 openipa abrt[23220]: saved core dump of pid 21631 (/usr/sbin/named) to /var/spool/abrt/ccpp-1311477445-21631.new/coredump (143396864 bytes)</div></div><div><br></div><div>Also, I
could see the following in my krb5kdc.log,</div><div><br></div><div><div>ul 24 06:20:46 openipa.hugayet.com krb5kdc[23721](Error): preauth pkinit failed to initialize: No realms configured correctly for pkinit support</div><div>Jul 24 06:20:46 openipa.hugayet.com krb5kdc[23721](info): setting up network...</div><div>Jul 24 06:20:46 openipa.hugayet.com krb5kdc[23721](info): listening on fd 9: udp 0.0.0.0.88 (pktinfo)</div><div>krb5kdc: setsockopt(10,IPV6_V6ONLY,1) worked</div><div>krb5kdc: No realms configured correctly for pkinit support - Cannot request packet info for udp socket address :: port 88</div><div>Jul 24 06:20:46 openipa.hugayet.com krb5kdc[23721](info): skipping unrecognized local address family 17</div><div>Jul 24 06:20:46 openipa.hugayet.com krb5kdc[23721](info): skipping unrecognized local address family 17</div><div>krb5kdc: setsockopt(10,IPV6_V6ONLY,1) worked</div><div>Jul 24 06:20:46 openipa.hugayet.com krb5kdc[23721](info): listening
on fd 10: udp fe80::6ab5:99ff:fec8:160%eth0.88</div><div>krb5kdc: setsockopt(11,IPV6_V6ONLY,1) worked</div><div>Jul 24 06:20:46 openipa.hugayet.com krb5kdc[23721](info): listening on fd 12: tcp 0.0.0.0.88</div><div>Jul 24 06:20:46 openipa.hugayet.com krb5kdc[23721](info): listening on fd 11: tcp ::.88</div><div>Jul 24 06:20:46 openipa.hugayet.com krb5kdc[23721](info): set up 4 sockets</div></div><div><br></div><div>Also, please note the following points,</div><div><br></div><div> ---- For the DHCP service, I have a cobbler server running the service which will use the FreeIPA server's DNS servicee.(with <b>ddns-update-style interim; </b>option in the dhcp configuration file)</div><div> ---- After seeing some permission related issues for named, I have given /var/named sufficient permission to named daemon for the folder.</div><div> ---- Disabled ipv6 for named as I don't use it anyway(OPTIONS="-4" in
/etc/sysconfig/named)</div><div><br></div><div>Thanks indeed for for all the help so far and waiting for your valuable input on this!</div><div><br></div><div>Regards,</div><div>Nidal</div><div><br><br>--- On <b>Wed, 5/18/11, nasir nasir <i><kollathodi@yahoo.com></i></b> wrote:<br><blockquote style="border-left: 2px solid rgb(16, 16, 255); margin-left: 5px; padding-left: 5px;"><br>From: nasir nasir <kollathodi@yahoo.com><br>Subject: Re: [Freeipa-users] FreeIPA for Linux desktop deployment<br>To: "Adam Young" <ayoung@redhat.com><br>Cc: freeipa-users@redhat.com<br>Date: Wednesday, May 18, 2011, 11:00 AM<br><br><div id="yiv1586787916"><table cellspacing="0" cellpadding="0" border="0"><tbody><tr><td valign="top" style="font:inherit;"><div>Adam,</div><div><br></div><div>I will look more in to this aspect and update later.</div><div><br></div>Big thanks to everyone for making me reach up to this point. I appreciate it tremendously. Now in my
test environement I have a working FreeIPA server, NFS server(which is and IPA client), 2 more IPA clients. All running RHEL 6.1 beta. <div><br></div><div><b>Following things work fine now,</b></div><div> </div><div> -- Centralized authentication and user/group management</div><div> -- Shared home folder automatically gets mounted to the client machine when the user login for the first time(Only catch is it needs to be created manually on the NFS server first)</div><div> -- User profiles are preserved in the home folder</div><div><br></div><div><b>Next
steps,</b></div><div><br></div><div> -- Try whether I can have this WITHOUT creating the home folder manually on the NFS server first</div><div> -- Replication of FreeIPA by adding one more server</div><div> -- Try out HBAC, Roles, Netgroups and other features of FreeIPA</div><div> -- Implement quota for user home folder</div><div><br></div><div>I will update the list about progress of all these later.</div><div><br></div><div>Thanks indeed to everyone once again!</div><div><br></div><div>Regards,</div><div>Nidal</div><div><br></div><div> <br><div><blockquote style="border-left:2px solid rgb(16, 16, 255);margin-left:5px;padding-left:5px;"><div id="yiv1586787916"><br>
I'm guessing that there is some policy enforced by the NFS server
here that lets you do something like this. <br>
...and here's the source code....<br>
<br>
<a rel="nofollow" class="yiv1586787916moz-txt-link-freetext" target="_blank" href="http://autofs5.sourcearchive.com/documentation/5.0.4-2/mount__nfs_8c-source.html">http://autofs5.sourcearchive.com/documentation/5.0.4-2/mount__nfs_8c-source.html</a><br>
Here's the comment right above the line that generates that message.<br>
<pre class="yiv1586787916fragment"><span class="yiv1586787916comment"> * If the "port" option is specified, then we don't want</span>
<span class="yiv1586787916comment"> * a bind mount. Use the "port" option if you want to</span>
<span class="yiv1586787916comment"> * avoid attempting a local bind mount, such as when</span>
<span class="yiv1586787916comment"> * tunneling NFS via localhost.</span></pre>
<br>
So no surprise that the behavior is different on the NFS server than
the rest of the cluster.<br>
<br>
<blockquote type="cite">
<table border="0" cellpadding="0" cellspacing="0">
<tbody>
<tr>
<td style="font:inherit;" valign="top">
<div>
<div style="font-family:arial;font-size:10pt;"> 27
May 17 07:45:14 hugayat automount[15767]: mount_mount:
mount(bind): calling mkdir_path /home/nasir</div>
<div style="font-family:arial;font-size:10pt;"> 28
May 17 07:45:14 hugayat automount[15767]: mount_mount:
mount(bind): calling mount --bind -s -o defaults
/xtra/home/nasir /home/nasir</div>
<div style="font-family:arial;font-size:10pt;"> 29
May 17 07:45:14 hugayat automount[15767]: mount_mount:
mount(bind): mounted /xtra/home/nasir type bind on
/home/nasir</div>
<div style="font-family:arial;font-size:10pt;font-weight:bold;"><br>
</div>
<div style="font-family:arial;font-size:10pt;"><b>2.
ssh -l rhel.cohort.org</b></div>
<div style="font-family:arial;font-size:10pt;font-weight:bold;"><br>
</div>
<div style="font-family:arial;font-size:10pt;">
<div> 7 May 17 07:46:06 rhel automount[15387]:
find_server: trying server uri <a rel="nofollow" class="yiv1586787916moz-txt-link-freetext">ldap://192.168.1.240</a></div>
<div> 8 May 17 07:46:06 rhel automount[15387]:
do_bind: lookup(ldap): auth_required: 1, sasl_mech
(null)</div>
<div> 9 May 17 07:46:06 rhel automount[15387]:
do_bind: lookup(ldap): ldap simple bind returned 0</div>
<div> 10 May 17 07:46:06 rhel automount[15387]:
get_query_dn: lookup(ldap): check search base list</div>
<div> 11 May 17 07:46:06 rhel automount[15387]:
get_query_dn: lookup(ldap): found search base under
cn=automount,dc=cohort,dc=org</div>
<div> 12 May 17 07:46:06 rhel automount[15387]:
get_query_dn: lookup(ldap): found query dn
automountmapname=auto.home,cn=default,cn=automount,dc=cohort,dc=org</div>
<div> 13 May 17 07:46:06 rhel automount[15387]:
connected to uri <a rel="nofollow" class="yiv1586787916moz-txt-link-freetext">ldap://192.168.1.240</a></div>
<div> 14 May 17 07:46:06 rhel automount[15387]:
lookup_one: lookup(ldap): searching for
"(&(objectclass=automount)(|(automountKey=nasir)(automountKey=/)(automountKey=\2A)))"
under "automountmapname=auto.home,
cn=default,cn=automount,dc=cohort,dc=org"</div>
<div> 15 May 17 07:46:06 rhel automount[15387]:
lookup_one: lookup(ldap): getting first entry for
automountKey="nasir"</div>
<div> 16 May 17 07:46:06 rhel automount[15387]:
lookup_one: lookup(ldap): examining first entry</div>
<div> 17 May 17 07:46:06 rhel automount[15387]:
lookup_mount: lookup(ldap): nasir ->
-fstype=nfs4,rw,sec=krb5,soft,rsize=8192,wsize=8192
hugayat.cohort.org:/xtra/home/&</div>
<div> 18 May 17 07:46:06 rhel automount[15387]:
parse_mount: parse(sun): expanded entry:
-fstype=nfs4,rw,sec=krb5,soft,rsize=8192,wsize=8192
hugayat.cohort.org:/xtra/home/nasir</div>
<div> 19 May 17 07:46:06 rhel automount[15387]:
parse_mount: parse(sun): gathered options:
fstype=nfs4,rw,sec=krb5,soft,rsize=8192,wsize=8192</div>
<div> 20 May 17 07:46:06 rhel automount[15387]:
parse_mount: parse(sun):
dequote("hugayat.cohort.org:/xtra/home/nasir") ->
hugayat.cohort.org:/xtra/home/nasir</div>
<div> 21 May 17 07:46:06 rhel automount[15387]:
parse_mount: parse(sun): core of entry:
options=fstype=nfs4,rw,sec=krb5,soft,rsize=8192,wsize=8192,
loc=hugayat.cohort.org:/xtra/home/nasir</div>
<div> 22 May 17 07:46:06 rhel automount[15387]:
sun_mount: parse(sun): mounting root /home,
mountpoint nasir, what
hugayat.cohort.org:/xtra/home/nasir, fstype nfs4,
options rw,sec=krb5,soft,rsize=8192,wsize=8 192</div>
<div> 23 May 17 07:46:06 rhel automount[15387]:
mount_mount: mount(nfs): root=/home name=nasir
what=hugayat.cohort.org:/xtra/home/nasir,
fstype=nfs4,
options=rw,sec=krb5,soft,rsize=8192,wsize=8192</div>
<div> 24 May 17 07:46:06 rhel automount[15387]:
mount_mount: mount(nfs): nfs
options="rw,sec=krb5,soft,rsize=8192,wsize=8192",
nosymlink=0, ro=0</div>
<div> 25 May 17 07:46:06 rhel automount[15387]:
mount_mount: mount(nfs): calling mkdir_path
/home/nasir</div>
<div> 26 May 17 07:46:06 rhel automount[15387]:
mount_mount: mount(nfs): calling mount -t nfs4 -s -o
rw,sec=krb5,soft,rsize=8192,wsize=8192
hugayat.cohort.org:/xtra/home/nasir /home/nasir</div>
<div> 27 May 17 07:46:06 rhel automount[15387]:
>><b> mount.nfs4: mounting
hugayat.cohort.org:/xtra/home/nasir failed, reason
given by server:</b></div>
<div><b> 28 May 17 07:46:06 rhel automount[15387]:
>> No such file or directory</b></div>
</div>
<div style="font-family:arial;font-size:10pt;font-weight:bold;"><br>
</div>
<div style="font-family:arial;font-size:10pt;font-weight:bold;"><br>
</div>
<div><font class="yiv1586787916Apple-style-span" face="arial" size="2">Please compare the lines between 20-30 in
both the cases. All the </font><font class="yiv1586787916Apple-style-span" face="arial" size="2">parameters
are same but in the first case it says the user
"nasir is local". What does it mean ? </font></div>
</div>
<div style="font-family:arial;font-size:10pt;"><b><br>
</b></div>
<div style="font-family:arial;font-size:10pt;">Thanks
and regards,</div>
<div style="font-family:arial;font-size:10pt;">Nidal</div>
<div style="font-family:arial;font-size:10pt;"><br>
</div>
<blockquote style="font-family:arial;font-size:10pt;border-left:2px solid rgb(16, 16, 255);margin-left:5px;padding-left:5px;"><br>
<div id="yiv1586787916">
<table border="0" cellpadding="0" cellspacing="0">
<tbody>
<tr>
<td style="font:inherit;" valign="top">
<div>Thanks again! To answer your queries,</div>
<div><br>
</div>
<div> -- I get the same error for <b>su -
nasir</b></div>
-- I don't think ssh is not creating
oddjobd ; see the error in the trailing mail
which I am getting in the konsole while trying
to login. It does try to create home folder
<div> -- The client IPA machine was created
with --mkhomedir switch. Also, I can see <b>pam_oddjob_mkhomedir.so
</b>entry in the system-auth and
password-auth files of pam(But not in ssh
file, though I manually tried once to insert
in ssh file and then it was trying to create
the home folder twice while SSHing !!).</div>
<div> -- As I said in previous mail,
Pre-created directories get autmounted and
setup correctly when I try to login to NFS
server(cohort.org.hugyat) but NOT to other
machines.</div>
<div> -- When autofs is disabled,
directories get created successfully in the
local hard disk on all the machines
configured with --mkhomedir switch</div>
<div><br>
</div>
<div>Any clue ?</div>
<div><br>
</div>
<div>Thanks and regards,<br>
Nidal</div>
<div><br>
<br>
<blockquote style="border-left:2px solid rgb(16, 16, 255);margin-left:5px;padding-left:5px;">
<div id="yiv1586787916">
<title></title>
Lets try to isolate it a little
further. If you log in to that machine
as root, and then do su - nasir, does it
let you create the directory or give you
the same error? I'm guessing it is ssh
that is complaining here. If the mount
point is set up correctly, you should be
able to crete and chown the /home/nasir
directory, either via odd job, or just
test it as root.<br>
<br>
What I am guessing is happening here is
that ssh is not triggereing the odd job
creation of the home directory. Either
that, or this particular IPA client was
run without the switch to create the
home-dir. If Automount is commented
out, does the /home/nasir directory get
created on the local disk?<br>
<br>
<br>
On 05/16/2011 09:19 PM, nasir nasir
wrote:
<blockquote type="cite">
<table border="0" cellpadding="0" cellspacing="0">
<tbody>
<tr>
<td style="font:inherit;" valign="top">
<div>Thanks again!</div>
<div><br>
</div>
<div>No! it allows auto mount
that pre created home folder
<b>ONLY to the NFS server</b>.
For e.g if I have <b>/xtra/home/nasir</b>
alread created, then it
automatically mounts while
login to NFS server ( ssh -l
nasir NFS_SERVER ). But when
I try to login as the same
user to some other machine (
ssh -l nasir
ANY_IPA_MACHINE) it gives
the following error,</div>
<div><br>
</div>
<div>
<div><b>[root@openipa ~]#
ssh -l nasir
192.168.1.222 -X</b></div>
<div><b><a rel="nofollow" class="yiv1586787916moz-txt-link-abbreviated">nasir@192.168.1.222</a>'s
password: </b></div>
<div><b>Creating home
directory for nasir.</b></div>
<div><b>Last login: Tue May
17 04:06:43 2011 from
openipa.cohort.org</b></div>
<div><b>Could not chdir to
home directory
/home/nasir: No such
file or directory</b></div>
<div><b>-sh-4.1$ ls</b></div>
</div>
<div><br>
</div>
<div>So it is not working
right ? Hope it is clear to
you now.</div>
<div><br>
</div>
<div>Thanks and regards,</div>
<div>Nidal</div>
<div><br>
</div>
<div><br>
</div>
<br>
<blockquote style="border-left:2px solid rgb(16, 16, 255);margin-left:5px;padding-left:5px;">
<div id="yiv1586787916">
<blockquote type="cite">
<table border="0" cellpadding="0" cellspacing="0">
<tbody>
<tr>
<td style="font:inherit;" valign="top">
<div>If I
manually
create one
home folder(
e.g <b>/xtra/home/abc</b>
) under than,
then I can
mount it, but
nothing can be
written to it
by the user as
it gives
permission
denied error.</div>
</td>
</tr>
</tbody>
</table>
</blockquote>
<br>
Yes, but it should allow
the root user to create
and chown the directory,
so the autocreation of
home dirs should work.<br>
<br>
</div>
<div class="yiv1586787916plainMail"><br>
</div>
</blockquote>
</td>
</tr>
</tbody>
</table>
</blockquote>
<br>
</div>
</blockquote>
</div>
</td>
</tr>
</tbody>
</table>
</div>
<br>
-----Inline Attachment Follows-----<br>
<br>
<div class="yiv1586787916plainMail">_______________________________________________<br>
Freeipa-users mailing list<br>
<a rel="nofollow">Freeipa-users@redhat.com</a><br>
<a rel="nofollow" target="_blank" href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a></div>
</blockquote>
</td>
</tr>
</tbody>
</table>
</blockquote>
<br>
</div></blockquote></div></div></td></tr></tbody></table></div><br>-----Inline Attachment Follows-----<br><br><div class="plainMail">_______________________________________________<br>Freeipa-users mailing list<br><a ymailto="mailto:Freeipa-users@redhat.com" href="/mc/compose?to=Freeipa-users@redhat.com">Freeipa-users@redhat.com</a><br><a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a></div></blockquote></div></td></tr></table>