<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-2">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div>
<div>Did you try tu run ypinit -c ?</div>
<div>Not sure now - it might be necessary to initialize the Nis subsystem.</div>
<div>O.</div>
<div><br>
</div>
<div><br>
</div>
<div>
<div style="font-size:9px; color:#575757">Odesláno ze Samsung Mobile</div>
</div>
<br>
<br>
-------- Původní zpráva --------<br>
Od: "Joseph, Matthew (EXP)" <br>
Datum:07. 01. 2014 15:52 (GMT+01:00) <br>
Komu: Petr Spacek ,Rob Crittenden ,dpal@redhat.com,freeipa-users@redhat.com <br>
Předmět: Re: [Freeipa-users] EXTERNAL: Re: NIS Compat issues <br>
<br>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">So looking at NIS documentation I noticed my /var/yp folder did not have the same folders/files as it should.<br>
It should have a Makefile, nicknames, binding (folder) and mydomainname (folder)<br>
<br>
I created a folder which matched my domainname and ypbind was finally able to start. But I can't do a ypcat since it can't find the maps which I would assume live under that domainname folder.<br>
<br>
Any ideas?<br>
<br>
-----Original Message-----<br>
From: freeipa-users-bounces@redhat.com [<a href="mailto:freeipa-users-bounces@redhat.com">mailto:freeipa-users-bounces@redhat.com</a>] On Behalf Of Joseph, Matthew (EXP)<br>
Sent: Tuesday, January 07, 2014 9:23 AM<br>
To: Petr Spacek; Rob Crittenden; dpal@redhat.com; freeipa-users@redhat.com<br>
Subject: Re: [Freeipa-users] EXTERNAL: Re: NIS Compat issues<br>
<br>
I forgot to show my current configuration.<br>
<br>
Yp.conf<br>
-----------------<br>
Domain mydomain.ca server primaryIPA<br>
Domain mydomain.ca server secondaryIPA<br>
<br>
/etc/sysconfig/network<br>
-------------------<br>
NISDOMAIN=mydomain.ca<br>
<br>
Nsswitch.conf <br>
-----------------------<br>
has "nis" added for passwd/group/automount<br>
<br>
I've been trying different combinations of adding the nsslapd-pluginarg0: 1023 and running ypserv on the same port.<br>
Should nsslapd and ypserv be running on the same port when I do the netstat command?<br>
<br>
-----Original Message-----<br>
From: Petr Spacek [<a href="mailto:pspacek@redhat.com">mailto:pspacek@redhat.com</a>]
<br>
Sent: Tuesday, January 07, 2014 6:59 AM<br>
To: Joseph, Matthew (EXP); Rob Crittenden; dpal@redhat.com; freeipa-users@redhat.com<br>
Subject: Re: [Freeipa-users] EXTERNAL: Re: NIS Compat issues<br>
<br>
On 7.1.2014 11:22, Joseph, Matthew (EXP) wrote:<br>
> When I run ypcat on the IPA servers it states that ypbind can't communicate.<br>
> I started ypbind on the secondary IPA server so now I can run ypcat.<br>
> Is running ypbind on the IPA servers necessary? According to all of the documentation I read it doesn't mention anything about ypbind on the servers.<br>
><br>
> Yup, I checked the status of the port to make sure nothing else was using it.<br>
> I configured it for an empty port below 1024.<br>
<br>
You can use command<br>
netstat -lpn (as root)<br>
and check if the process is listening on the correct port and interface.<br>
<br>
Petr^2 Spacek<br>
<br>
> -----Original Message-----<br>
> From: Rob Crittenden [<a href="mailto:rcritten@redhat.com">mailto:rcritten@redhat.com</a>]<br>
> Sent: Monday, January 06, 2014 6:13 PM<br>
> To: Joseph, Matthew (EXP); dpal@redhat.com; freeipa-users@redhat.com<br>
> Subject: Re: [Freeipa-users] EXTERNAL: Re: NIS Compat issues<br>
><br>
> Joseph, Matthew (EXP) wrote:<br>
>> Hello,<br>
>><br>
>> I can add the old UNIX servers using NIS to the secondary IPA server but not the primary.<br>
>> The servers can ping the primary with no issues.<br>
>><br>
>> I didn't think the IPA servers could run ypcat? Either way neither of the servers can run the ypcat commands.<br>
><br>
> Can't run them how?<br>
><br>
>> Nope, ypbind was stopped when those errors came up.<br>
><br>
> Can you confirm that nothing else is bound to the port?<br>
><br>
> rob<br>
><br>
>><br>
>> Matt<br>
>><br>
>> -----Original Message-----<br>
>> From: Rob Crittenden [<a href="mailto:rcritten@redhat.com">mailto:rcritten@redhat.com</a>]<br>
>> Sent: Thursday, January 02, 2014 2:58 PM<br>
>> To: Joseph, Matthew (EXP); dpal@redhat.com; freeipa-users@redhat.com<br>
>> Subject: Re: [Freeipa-users] EXTERNAL: Re: NIS Compat issues<br>
>><br>
>> Joseph, Matthew (EXP) wrote:<br>
>>> Hello,<br>
>>><br>
>>> All of the IPA services are running.<br>
>>><br>
>>> When I tried running the ipa-compat-manage enable and ipa-nis-manage<br>
>>> enable they are both loaded and running.<br>
>><br>
>> On the IPA master you should be able to run something like:<br>
>><br>
>> $ ypcat -h `hostname` -d <your nis domain name> passwd<br>
>><br>
>> This will confirm basic operation on the server.<br>
>><br>
>> If you can run the same on a client it will rule out firewall issues.<br>
>><br>
>> Is a ypbind process already running on these clients? That might<br>
>> explain the 'address in use' error.<br>
>><br>
>> rob<br>
>><br>
>>><br>
>>> The firewall is not the issue, I am positive about that.<br>
>>><br>
>>> What do you mean by looking at the compat tree from the IPA server?<br>
>>><br>
>>> Matt<br>
>>><br>
>>> *From:*freeipa-users-bounces@redhat.com<br>
>>> [<a href="mailto:freeipa-users-bounces@redhat.com">mailto:freeipa-users-bounces@redhat.com</a>] *On Behalf Of *Dmitri Pal<br>
>>> *Sent:* Thursday, January 02, 2014 12:13 PM<br>
>>> *To:* freeipa-users@redhat.com<br>
>>> *Subject:* EXTERNAL: Re: [Freeipa-users] NIS Compat issues<br>
>>><br>
>>> On 01/02/2014 11:05 AM, Joseph, Matthew (EXP) wrote:<br>
>>><br>
>>> Hello,<br>
>>><br>
>>> I've recently had to restart my IPA servers and my NIS compatibility<br>
>>> mode has stopped working.<br>
>>><br>
>>> I've configured my IPA server to run in NIS compatibility mode by<br>
>>> doing the following.<br>
>>><br>
>>> [root@ipaserver ~]# ipa-nis-manage enable<br>
>>><br>
>>> [root@ipaserver ~]# ipa-compat-manage enable<br>
>>><br>
>>> Restart the DNS and Directory Server service:<br>
>>><br>
>>> [root@server ~]# service restart rpcbind<br>
>>><br>
>>> [root@server ~]# service restart dirsrv<br>
>>><br>
>>> On my NIS clients I have the following setup in the yp.conf file.<br>
>>><br>
>>> domain domainname.ca<br>
>>> server ipaservername.domainname.ca<br>
>>><br>
>>> I tried just running the broadcast option but with no luck.<br>
>>><br>
>>> When I try to do a service ypbind start on my NIS clients it takes a<br>
>>> few minutes to finally fail.<br>
>>><br>
>>> When I tried an yptest says "Can't communicate with ypbind" which<br>
>>> makes sense since ypbind will not start.<br>
>>><br>
>>> On the NIS client in the messages file it says the following;<br>
>>><br>
>>> Ypbind: broadcast: RPC: Timed Out<br>
>>><br>
>>> Cannot bind UDP: Address already in use<br>
>>><br>
>>> Nothing has changed on my IPA server/configuration so I have no idea<br>
>>> why this stopped working.<br>
>>><br>
>>> Any suggestions?<br>
>>><br>
>>><br>
>>> Please check if the IPA is running, the DS is running. Check the logs<br>
>>> that the compat plugin is loaded and working.<br>
>>> You can also try looking at the compat tree from the server itself to<br>
>>> verify that the plugin, at least the DS part is functional.<br>
>>><br>
>>> This generally smells as a firewall issue but I have not way to prove<br>
>>> or disprove the theory.<br>
>>><br>
>>><br>
>>> Matt<br>
<br>
_______________________________________________<br>
Freeipa-users mailing list<br>
Freeipa-users@redhat.com<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
<br>
_______________________________________________<br>
Freeipa-users mailing list<br>
Freeipa-users@redhat.com<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
</div>
</span></font>
</body>
</html>