<div dir="ltr">Hi Martin <div><br></div><div>I am happy to provide the necessary information. What packages should i check for? As for IPA we are IPA CA being signed with other CA</div><div><br></div><div>Thank You</div>
</div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jan 27, 2016 at 2:24 AM, Martin Kosek <span dir="ltr"><<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 01/26/2016 09:45 PM, Ash Alam wrote:<br>
> I didnt want to dig up an old thread but i am running into this issue. The<br>
> old thread points to Pki 10.2.6 as the solution but i am not seeing that<br>
> package on centos 7.2.<br>
><br>
> STDERR: ipa.ipaserver.install.cainstance.CAInstance: CRITICAL Failed to<br>
> configure CA instance: Command ''/usr/sbin/pkispawn' '-s' 'CA' '-f'<br>
> '/tmp/tmpHfdvFD'' returned non-zero exit status 1<br>
<br>
</span>CCing David and Endi, they might have an idea what is wrong. There were several<br>
recent fixes, to again fix RHEL-6 to RHEL-7 migration, we would need to check<br>
if you have them installed. As for your RHEL-6 IPA setup, is it running with<br>
External CA, i.e. IPA CA with being signed with other CA?<br>
<div class="HOEnZb"><div class="h5"><br>
><br>
> On Tue, Jan 26, 2016 at 12:14 PM, Ash Alam <<a href="mailto:aalam@paperlesspost.com">aalam@paperlesspost.com</a>> wrote:<br>
><br>
>> thank you! Out of curiosity has anyone been able to automate this using<br>
>> chef/puppet etc?<br>
>><br>
>> On Tue, Jan 26, 2016 at 10:56 AM, Martin Kosek <<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a>> wrote:<br>
>><br>
>>> Did you follow the instructions in the error message? There is also a<br>
>>> longer<br>
>>> description here:<br>
>>><br>
>>><br>
>>> <a href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/upgrading.html#migrating-ipa-proc" rel="noreferrer" target="_blank">https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/upgrading.html#migrating-ipa-proc</a><br>
>>><br>
>>> Martin<br>
>>><br>
>>> On 01/26/2016 04:38 PM, Ash Alam wrote:<br>
>>>> I wanted to follow up on this as i finally gotten around to doing the<br>
>>>> upgrade. I an running into this error. I also found a bugzilla ticket.<br>
>>> Do<br>
>>>> you have to do some type of schema upgrade like you do with active<br>
>>>> directory?<br>
>>>><br>
>>>> <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1235766" rel="noreferrer" target="_blank">https://bugzilla.redhat.com/show_bug.cgi?id=1235766</a><br>
>>>><br>
>>>> STDERR: ipa : CRITICAL The master CA directory server does<br>
>>> not<br>
>>>> have necessary schema. Please copy the following script to all CA<br>
>>> masters<br>
>>>> and run it on them: /usr/share/ipa/copy-schema-to-ca.py<br>
>>>><br>
>>>> If you are certain that this is a false positive, use<br>
>>>> --skip-schema-check.<br>
>>>><br>
>>>> ipa.ipapython.install.cli.install_tool(Replica): ERROR IPA schema<br>
>>>> missing on master CA directory server<br>
>>>><br>
>>>><br>
>>>><br>
>>>> Thank You<br>
>>>><br>
>>>><br>
>>>><br>
>>>><br>
>>>> On Fri, Nov 20, 2015 at 11:13 AM, Martin Kosek <<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a>><br>
>>> wrote:<br>
>>>><br>
>>>>> On 11/20/2015 04:08 PM, Ash Alam wrote:<br>
>>>>><br>
>>>>>> Most of the clients in my env are centos 6.6 with ipa 3.0.0 client<br>
>>>>>> installed. I<br>
>>>>>> if bring up a replica on centos 7.2 with ipa 4.2.3 server and then<br>
>>> start<br>
>>>>>> phasing out the older 3.0.0 servers. Will the client that are still<br>
>>>>>> running the<br>
>>>>>> older client software still work?<br>
>>>>>><br>
>>>>><br>
>>>>> It should, yes. It is expected that there are RHEL/CentOS-6 clients<br>
>>> with<br>
>>>>> RHEL-7 FreeIPA servers. The older clients just won't be able to use the<br>
>>>>> newest features.<br>
>>>>><br>
>>>>><br>
>>>>>> On Fri, Nov 20, 2015 at 4:31 AM, Martin Kosek <<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a><br>
>>>>>> <mailto:<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a>>> wrote:<br>
>>>>>><br>
>>>>>> On 11/19/2015 11:03 PM, Ash Alam wrote:<br>
>>>>>><br>
>>>>>> Hello All<br>
>>>>>><br>
>>>>>> I am looking for some advice on upgrading. Currently our<br>
>>> FreeIPA<br>
>>>>>> servers are<br>
>>>>>> 3.0.0 on centos 6.6. We are looking to go to 4.2.3 Centos7.<br>
>>> This<br>
>>>>>> upgrade path<br>
>>>>>> is not possible per IPA documentation. Minimum version<br>
>>> required<br>
>>>>>> is 3.3.x. I<br>
>>>>>> have also found that cenos6 does not provide anything past<br>
>>> 3.0.0.<br>
>>>>>><br>
>>>>>><br>
>>>>>> And it won't. There are no plans in updating FreeIPA version in<br>
>>>>>> RHEL/CentOS-6.x, we encourage people who want the new features to<br>
>>>>>> migrate<br>
>>>>>> to RHEL-7.x:<br>
>>>>>><br>
>>>>>><br>
>>>>>><br>
>>> <a href="http://www.freeipa.org/page/Howto/Migration#Migrating_Identity_Management_in_RHEL.2FCentOS" rel="noreferrer" target="_blank">http://www.freeipa.org/page/Howto/Migration#Migrating_Identity_Management_in_RHEL.2FCentOS</a><br>
>>>>>><br>
>>>>>><br>
>>>>>><br>
>>> <a href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/upgrading.html#migrating-ipa-proc" rel="noreferrer" target="_blank">https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/upgrading.html#migrating-ipa-proc</a><br>
>>>>>><br>
>>>>>> If you want to wait on CentOS-7.2, it should be in works now:<br>
>>>>>> <a href="http://seven.centos.org/2015/11/rhel-7-2-released-today/" rel="noreferrer" target="_blank">http://seven.centos.org/2015/11/rhel-7-2-released-today/</a><br>
>>>>>><br>
>>>>>> One idea is to upgrade to 3.3.x first and then upgrade to<br>
>>> 4.2.3<br>
>>>>>> on centos7.<br>
>>>>>> This is harder since centos does not provide this. The other<br>
>>>>>> issue is if<br>
>>>>>> 3.0/3.3 client will be supported with 4.2.3 server.<br>
>>>>>><br>
>>>>>><br>
>>>>>> The right way is to migrate via creating replicas in<br>
>>> RHEL/CentOS-7.x<br>
>>>>>> and<br>
>>>>>> slowly deprecating RHEL/CentOS-6 ones. Detailed procedure in the<br>
>>>>>> links above.<br>
>>>>>><br>
>>>>>><br>
>>>>>><br>
>>>>><br>
>>>><br>
>>><br>
>>><br>
>><br>
><br>
<br>
</div></div></blockquote></div><br></div>