<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body smarttemplateinserted="true" bgcolor="#FFFFFF" text="#000000">
<div id="smartTemplate4-template">This is what the non-functional
version looked like:<br>
<font color="#660000"><tt>includedir
/var/lib/sss/pubconf/krb5.include.d/</tt><tt><br>
</tt><tt><br>
</tt><tt>[logging]</tt><tt><br>
</tt><tt> default = <a class="moz-txt-link-freetext" href="FILE:/var/log/krb5libs.log">FILE:/var/log/krb5libs.log</a></tt><tt><br>
</tt><tt> kdc = <a class="moz-txt-link-freetext" href="FILE:/var/log/krb5kdc.log">FILE:/var/log/krb5kdc.log</a></tt><tt><br>
</tt><tt> admin_server = <a class="moz-txt-link-freetext" href="FILE:/var/log/kadmind.log">FILE:/var/log/kadmind.log</a></tt><tt><br>
</tt><tt><br>
</tt><tt>[libdefaults]</tt><tt><br>
</tt><tt> default_realm = CLOUD.COM</tt><tt><br>
</tt><tt> dns_lookup_realm = false</tt><tt><br>
</tt><tt> dns_lookup_kdc = true</tt><tt><br>
</tt><tt> rdns = false</tt><tt><br>
</tt><tt> ticket_lifetime = 24h</tt><tt><br>
</tt><tt> forwardable = yes</tt><tt><br>
</tt><tt><br>
</tt><tt>[realms]</tt><tt><br>
</tt><tt> CLIFF.CLOUDBURRITO.COM = {</tt><tt><br>
</tt><tt> kdc =
i-31f62969.ipa-server.us-west-1.cliff.cloudburrito.com:88</tt><tt><br>
</tt><tt> master_kdc =
i-31f62969.ipa-server.us-west-1.cliff.cloudburrito.com:88</tt><tt><br>
</tt><tt> admin_server =
i-31f62969.ipa-server.us-west-1.cliff.cloudburrito.com:749</tt><tt><br>
</tt><tt> default_domain = cliff.cloudburrito.com</tt><tt><br>
</tt><tt> pkinit_anchors = <a class="moz-txt-link-freetext" href="FILE:/etc/ipa/ca.crt">FILE:/etc/ipa/ca.crt</a></tt><tt><br>
</tt><tt>}</tt><tt><br>
</tt><tt><br>
</tt><tt> CLOUD.COM = {</tt><tt><br>
</tt><tt> kdc = i-6775b715.ipa-server.us-east-1.cloud.com</tt><tt><br>
</tt><tt> kdc = i-32e87151.ipa-server.us-east-1.cloud.com</tt><tt><br>
</tt><tt> admin_server =
i-31f62969.ipa-server.us-west-1.cliff.cloudburrito.com:749</tt><tt><br>
</tt><tt> }</tt><tt><br>
</tt><tt><br>
</tt><tt>[domain_realm]</tt><tt><br>
</tt><tt> .cliff.cloudburrito.com = CLIFF.CLOUDBURRITO.COM</tt><tt><br>
</tt><tt> cliff.cloudburrito.com = CLIFF.CLOUDBURRITO.COM</tt><tt><br>
</tt><tt><br>
</tt><tt> cloud.com = CLOUD.COM</tt><tt><br>
</tt><tt> .cloud.com = CLOUD.COM</tt><tt><br>
</tt><tt>[dbmodules]</tt><tt><br>
</tt><tt> CLIFF.CLOUDBURRITO.COM = {</tt><tt><br>
</tt><tt> db_library = ipadb.so</tt><tt><br>
</tt><tt> }</tt></font><br>
<br>
This is what I did to fix it:<br>
<font color="#660000"><tt>--- /etc/krb5.conf.orig 2014-04-08
12:33:01.376525373 -0400</tt><tt><br>
</tt><tt>+++ /etc/krb5.conf 2014-04-08 12:33:33.214975855
-0400</tt><tt><br>
</tt><tt>@@ -6,7 +6,7 @@</tt><tt><br>
</tt><tt> admin_server = <a class="moz-txt-link-freetext" href="FILE:/var/log/kadmind.log">FILE:/var/log/kadmind.log</a></tt><tt><br>
</tt><tt> </tt><tt><br>
</tt><tt> [libdefaults]</tt><tt><br>
</tt><tt>- default_realm = CLOUD.COM</tt><tt><br>
</tt><tt>+ default_realm = CLIFF.CLOUDBURRITO.COM</tt><tt><br>
</tt><tt> dns_lookup_realm = false</tt><tt><br>
</tt><tt> dns_lookup_kdc = true</tt><tt><br>
</tt><tt> rdns = false</tt><tt><br>
</tt><tt>@@ -22,18 +22,10 @@</tt><tt><br>
</tt><tt> pkinit_anchors = <a class="moz-txt-link-freetext" href="FILE:/etc/ipa/ca.crt">FILE:/etc/ipa/ca.crt</a></tt><tt><br>
</tt><tt> }</tt><tt><br>
</tt><tt> </tt><tt><br>
</tt><tt>- CLOUD.COM = {</tt><tt><br>
</tt><tt>- kdc = i-6775b715.ipa-server.us-east-1.cloud.com</tt><tt><br>
</tt><tt>- kdc = i-32e87151.ipa-server.us-east-1.cloud.com</tt><tt><br>
</tt><tt>- admin_server =
i-31f62969.ipa-server.us-west-1.cliff.cloudburrito.com:749</tt><tt><br>
</tt><tt>- }</tt><tt><br>
</tt><tt>-</tt><tt><br>
</tt><tt> [domain_realm]</tt><tt><br>
</tt><tt> .cliff.cloudburrito.com = CLIFF.CLOUDBURRITO.COM</tt><tt><br>
</tt><tt> cliff.cloudburrito.com = CLIFF.CLOUDBURRITO.COM</tt><tt><br>
</tt><tt> </tt><tt><br>
</tt><tt>- cloud.com = CLOUD.COM</tt><tt><br>
</tt><tt>- .cloud.com = CLOUD.COM</tt><tt><br>
</tt><tt> [dbmodules]</tt><tt><br>
</tt><tt> CLIFF.CLOUDBURRITO.COM = {</tt><tt><br>
</tt><tt> db_library = ipadb.so</tt></font><br>
<br>
</div>
-Patrick<br>
<div id="smartTemplate4-quoteHeader"><br>
<hr>
<div><b>From: </b>Rob Crittenden <a class="moz-txt-link-rfc2396E" href="mailto:rcritten@redhat.com"><rcritten@redhat.com></a></div>
<div><b>Sent: </b> 2014-04-08 13:33:53 E</div>
<div><b>To: </b>Patrick Hemmer <a class="moz-txt-link-rfc2396E" href="mailto:freeipa@stormcloud9.net"><freeipa@stormcloud9.net></a>,
<a class="moz-txt-link-abbreviated" href="mailto:freeipa-users@redhat.com">freeipa-users@redhat.com</a></div>
<div><b>Subject: </b>Re: [Freeipa-users]
/var/kerberos/krb5kdc/principal missing</div>
<br>
</div>
<blockquote cite="mid:53443301.5030207@redhat.com" type="cite">Patrick
Hemmer wrote:
<br>
<blockquote type="cite">Figured it out.
<br>
Somehow during the upgrade process, the default_realm changed to
one of
<br>
our other domains we use. I'm guessing some RPM postinstall
script
<br>
pulled the domain out of sssd.conf as that's the only place on
the box
<br>
where that domain is mentioned. We don't touch krb5.conf with
any sort
<br>
of configuration management utility.
<br>
<br>
Anyway, after removing the domain from the krb5.conf and
restoring the
<br>
original settings, ipa started up normally.
<br>
</blockquote>
<br>
That's really strange.. I wonder if authconfig is doing something.
What exactly did the file look like? We do try to update it to fix
the dbmodules line but we already know the realm and domain from
/etc/ipa/default.conf.
<br>
<br>
rob
<br>
<br>
<blockquote type="cite">
<br>
-Patrick
<br>
<br>
<br>
------------------------------------------------------------------------
<br>
*From: *Patrick Hemmer <a class="moz-txt-link-rfc2396E" href="mailto:freeipa@stormcloud9.net"><freeipa@stormcloud9.net></a>
<br>
*Sent: * 2014-04-08 11:52:34 E
<br>
*To: *freeipa-users@redhat.com
<br>
*Subject: *[Freeipa-users] /var/kerberos/krb5kdc/principal
missing
<br>
<br>
<blockquote type="cite">I'm having the exact same issue as
<br>
<a class="moz-txt-link-freetext" href="http://www.redhat.com/archives/freeipa-users/2013-October/msg00009.html">http://www.redhat.com/archives/freeipa-users/2013-October/msg00009.html</a>
<br>
I upgraded from RHEL-6.3 to RHEL-6.5, and now FreeIPA won't
start due
<br>
to kadmind not starting.
<br>
<br>
The kadmind.log contains an extremely unhelpful:
<br>
Apr 08 11:31:20 i-31f62969 kadmind[20850](Error): No such file
or
<br>
directory while initializing, aborting
<br>
<br>
Stracing `/usr/sbin/kadmind -P /var/run/kadmind.pid` results
in:
<br>
open("/var/kerberos/krb5kdc/principal", O_RDONLY) = -1 ENOENT
(No such
<br>
file or directory)
<br>
gettimeofday({1396971844, 51536}, NULL) = 0
<br>
open("/etc/localtime", O_RDONLY) = 4
<br>
fstat(4, {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
<br>
fstat(4, {st_mode=S_IFREG|0644, st_size=3519, ...}) = 0
<br>
mmap(NULL, 4096, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_ANONYMOUS, -1,
<br>
0) = 0x7f25440dd000
<br>
read(4,
<br>
"TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\4\0\0\0\0"...,
<br>
4096) = 3519
<br>
lseek(4, -2252, SEEK_CUR) = 1267
<br>
read(4,
<br>
"TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\5\0\0\0\5\0\0\0\0"...,
<br>
4096) = 2252
<br>
close(4) = 0
<br>
munmap(0x7f25440dd000, 4096) = 0
<br>
write(3, "Apr 08 11:44:04 i-31f62969 kadmi"..., 105) = 105
<br>
write(2, "kadmind: No such file or directo"..., 64kadmind: No
such
<br>
file or directory while initializing, aborting) = 64
<br>
close(3) = 0
<br>
munmap(0x7f25440df000, 4096) = 0
<br>
exit_group(1) = ?
<br>
<br>
As requested in the linked thread, the dbmodules section looks
like this:
<br>
[dbmodules]
<br>
CLIFF.CLOUDBURRITO.COM = {
<br>
db_library = ipadb.so
<br>
}
<br>
<br>
Another important item of note, I have another IPA server
which has
<br>
not been upgraded from 6.3 yet, and the file is missing there
too, but
<br>
kadmind is currently running just fine...
<br>
<br>
Ideas?
<br>
<br>
-Patrick
<br>
<br>
<br>
_______________________________________________
<br>
Freeipa-users mailing list
<br>
<a class="moz-txt-link-abbreviated" href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a>
<br>
<a class="moz-txt-link-freetext" href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a>
<br>
</blockquote>
<br>
<br>
<br>
_______________________________________________
<br>
Freeipa-users mailing list
<br>
<a class="moz-txt-link-abbreviated" href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a>
<br>
<a class="moz-txt-link-freetext" href="https://www.redhat.com/mailman/listinfo/freeipa-users">https://www.redhat.com/mailman/listinfo/freeipa-users</a>
<br>
<br>
</blockquote>
<br>
</blockquote>
<br>
</body>
</html>