<div dir="ltr"><div><div><div><div><div># getcert list <br>returns 9 request ID. All 9 are in status "MONITORING" and expire after 2017.<br></div>So no expired certificate.<br></div><br>Number of certificates and requests being tracked: 9.<br>Request ID '20150313092422':<br> status: MONITORING<br> stuck: no<br> key pair storage: type=NSSDB,location='/etc/dirsrv/slapd-BIOINF-LOCAL',nickname='Server-Cert',token='NSS Certificate DB',pinfile='/etc/dirsrv/slapd-BIOINF-LOCAL/pwdfile.txt'<br> certificate: type=NSSDB,location='/etc/dirsrv/slapd-BIOINF-LOCAL',nickname='Server-Cert',token='NSS Certificate DB'<br> CA: IPA<br> issuer: CN=Certificate Authority,O=BIOINF.LOCAL<br> subject: CN=lead.bioinf.local,O=BIOINF.LOCAL<br> expires: 2017-03-13 09:24:21 UTC<br> key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br> eku: id-kp-serverAuth,id-kp-clientAuth<br> pre-save command: <br> post-save command: /usr/lib64/ipa/certmonger/restart_dirsrv BIOINF-LOCAL<br> track: yes<br> auto-renew: yes<br>Request ID '20150313092456':<br> status: MONITORING<br> stuck: no<br> key pair storage: type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS Certificate DB',pinfile='/etc/httpd/alias/pwdfile.txt'<br> certificate: type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS Certificate DB'<br> CA: IPA<br> issuer: CN=Certificate Authority,O=BIOINF.LOCAL<br> subject: CN=lead.bioinf.local,O=BIOINF.LOCAL<br> expires: 2017-03-13 09:24:56 UTC<br> key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br> eku: id-kp-serverAuth,id-kp-clientAuth<br> pre-save command: <br> post-save command: /usr/lib64/ipa/certmonger/restart_httpd<br> track: yes<br> auto-renew: yes<br>Request ID '20150710083112':<br> status: MONITORING<br> stuck: no<br> key pair storage: type=NSSDB,location='/etc/pki/nssdb',nickname='Server-Cert',token='NSS Certificate DB'<br> certificate: type=NSSDB,location='/etc/pki/nssdb',nickname='Server-Cert',token='NSS Certificate DB'<br> CA: IPA<br> issuer: CN=Certificate Authority,O=BIOINF.LOCAL<br> subject: CN=lead.bioinf.local,O=BIOINF.LOCAL<br> expires: 2017-07-10 08:31:16 UTC<br> principal name: host/lead.bioinf.local@BIOINF.LOCAL<br> key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br> eku: id-kp-serverAuth,id-kp-clientAuth<br> pre-save command: <br> post-save command: <br> track: yes<br> auto-renew: yes<br>Request ID '20160106131740':<br> status: MONITORING<br> stuck: no<br> key pair storage: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='auditSigningCert cert-pki-ca',token='NSS Certificate DB',pin set<br> certificate: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='auditSigningCert cert-pki-ca',token='NSS Certificate DB'<br> CA: dogtag-ipa-ca-renew-agent<br> issuer: CN=Certificate Authority,O=BIOINF.LOCAL<br> subject: CN=CA Audit,O=BIOINF.LOCAL<br> expires: 2017-03-02 09:24:01 UTC<br> key usage: digitalSignature,nonRepudiation<br> pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad<br> post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "auditSigningCert cert-pki-ca"<br> track: yes<br> auto-renew: yes<br>Request ID '20160106131741':<br> status: MONITORING<br> stuck: no<br> key pair storage: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='ocspSigningCert cert-pki-ca',token='NSS Certificate DB',pin set<br> certificate: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='ocspSigningCert cert-pki-ca',token='NSS Certificate DB'<br> CA: dogtag-ipa-ca-renew-agent<br> issuer: CN=Certificate Authority,O=BIOINF.LOCAL<br> subject: CN=OCSP Subsystem,O=BIOINF.LOCAL<br> expires: 2017-03-02 09:24:00 UTC<br> key usage: digitalSignature,nonRepudiation,keyCertSign,cRLSign<br> eku: id-kp-OCSPSigning<br> pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad<br> post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "ocspSigningCert cert-pki-ca"<br> track: yes<br> auto-renew: yes<br>Request ID '20160106131742':<br> status: MONITORING<br> stuck: no<br> key pair storage: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='subsystemCert cert-pki-ca',token='NSS Certificate DB',pin set<br> certificate: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='subsystemCert cert-pki-ca',token='NSS Certificate DB'<br> CA: dogtag-ipa-ca-renew-agent<br> issuer: CN=Certificate Authority,O=BIOINF.LOCAL<br> subject: CN=CA Subsystem,O=BIOINF.LOCAL<br> expires: 2017-03-02 09:24:01 UTC<br> key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br> eku: id-kp-serverAuth,id-kp-clientAuth<br> pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad<br> post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "subsystemCert cert-pki-ca"<br> track: yes<br> auto-renew: yes<br>Request ID '20160106131743':<br> status: MONITORING<br> stuck: no<br> key pair storage: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='caSigningCert cert-pki-ca',token='NSS Certificate DB',pin set<br> certificate: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='caSigningCert cert-pki-ca',token='NSS Certificate DB'<br> CA: dogtag-ipa-ca-renew-agent<br> issuer: CN=Certificate Authority,O=BIOINF.LOCAL<br> subject: CN=Certificate Authority,O=BIOINF.LOCAL<br> expires: 2035-03-13 09:23:59 UTC<br> key usage: digitalSignature,nonRepudiation,keyCertSign,cRLSign<br> pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad<br> post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "caSigningCert cert-pki-ca"<br> track: yes<br> auto-renew: yes<br>Request ID '20160106131744':<br> status: MONITORING<br> stuck: no<br> key pair storage: type=NSSDB,location='/etc/httpd/alias',nickname='ipaCert',token='NSS Certificate DB',pinfile='/etc/httpd/alias/pwdfile.txt'<br> certificate: type=NSSDB,location='/etc/httpd/alias',nickname='ipaCert',token='NSS Certificate DB'<br> CA: dogtag-ipa-ca-renew-agent<br> issuer: CN=Certificate Authority,O=BIOINF.LOCAL<br> subject: CN=IPA RA,O=BIOINF.LOCAL<br> expires: 2017-03-02 09:24:16 UTC<br> key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br> eku: id-kp-serverAuth,id-kp-clientAuth<br> pre-save command: /usr/lib64/ipa/certmonger/renew_ra_cert_pre<br> post-save command: /usr/lib64/ipa/certmonger/renew_ra_cert<br> track: yes<br> auto-renew: yes<br>Request ID '20160106131745':<br> status: MONITORING<br> stuck: no<br> key pair storage: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='Server-Cert cert-pki-ca',token='NSS Certificate DB',pin set<br> certificate: type=NSSDB,location='/etc/pki/pki-tomcat/alias',nickname='Server-Cert cert-pki-ca',token='NSS Certificate DB'<br> CA: dogtag-ipa-renew-agent<br> issuer: CN=Certificate Authority,O=BIOINF.LOCAL<br> subject: CN=lead.bioinf.local,O=BIOINF.LOCAL<br> expires: 2017-03-02 09:24:00 UTC<br> key usage: digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment<br> eku: id-kp-serverAuth<br> pre-save command: /usr/lib64/ipa/certmonger/stop_pkicad<br> post-save command: /usr/lib64/ipa/certmonger/renew_ca_cert "Server-Cert cert-pki-ca"<br> track: yes<br> auto-renew: yes<br><br><br>
Do you use IPA with externally signed CA cert? Are they valid?<br></div>I don't think (but I don't know how to check this to be sure ?)<br><br></div>Thx for your help !<br><br></div>Seli<br></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Jun 3, 2016 at 1:15 PM, Petr Vobornik <span dir="ltr"><<a href="mailto:pvoborni@redhat.com" target="_blank">pvoborni@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 06/03/2016 11:11 AM, seli irithyl wrote:<br>
> Sorry Martin,<br>
> I rebooted the IdM server:<br>
> [root@lead sssd]# ipactl status<br>
> Directory Service: RUNNING<br>
> krb5kdc Service: RUNNING<br>
> kadmin Service: RUNNING<br>
> ipa_memcached Service: RUNNING<br>
> httpd Service: RUNNING<br>
> pki-tomcatd Service: RUNNING<br>
> ipa-otpd Service: RUNNING<br>
> ipa: INFO: The ipactl command was successful<br>
><br>
> I checked DNS and it is ok<br>
><br>
> I can login from any host.<br>
><br>
> Unfortunately when trying to run any ipa command:<br>
> [root@lead ~]# ipa service-find lead.bioinf.local<br>
> ipa: ERROR: cert validation failed for<br>
> "E=root@lead.bioinf.local,CN=lead.bioinf.local,OU=SomeOrganizationalUnit,O=SomeOrganization,L=SomeCity,ST=SomeState,C=--"<br>
> ((SEC_ERROR_CA_CERT_INVALID) Issuer certificate is invalid.)<br>
> ipa: ERROR: cannot connect to '<a href="https://lead.bioinf.local/ipa/json" rel="noreferrer" target="_blank">https://lead.bioinf.local/ipa/json</a>':<br>
> (SEC_ERROR_CA_CERT_INVALID) Issuer certificate is invalid.<br>
><br>
> Is anybody has an idea on where and what to check next ?<br>
> Thx,<br>
><br>
> Seli<br>
><br>
<br>
</span>does<br>
# getcert list<br>
<br>
show any expired certificate?<br>
<br>
Do you use IPA with externally signed CA cert? Are they valid?<br>
<span class="im HOEnZb"><br>
><br>
><br>
> On Tue, May 31, 2016 at 8:33 AM, Martin Kosek <<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a><br>
</span><div class="HOEnZb"><div class="h5">> <mailto:<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a>>> wrote:<br>
><br>
> Hello Seli,<br>
><br>
> Please reply to mailing list directly so that others can benefit from the<br>
> thread as well.<br>
><br>
> Thanks,<br>
> Martin<br>
><br>
> On 05/30/2016 06:17 PM, seli irithyl wrote:<br>
> > Freeipa version : 4.2.0-15.0.1.el7.centos.6.1<br>
> > FF: 45.1.1<br>
> > Could this problem be related to mod_ssl and mod_nss for httpd ?<br>
> > Looking the logs, it seems there are lots of problems, here are some<br>
> parts that<br>
> > look strange to me (and are probably unrelated) :<br>
> > 1 sssd:<br>
> > 1.1 krb5_child.log<br>
> > (Mon May 30 17:18:05 2016) [[sssd[krb5_child[32832]]]]<br>
> [unpack_buffer]<br>
> > (0x0100): cmd [249] uid [1713400053] gid [1713400053] validate [true]<br>
> enterprise<br>
> > principal [false] offline [false] UPN [koto@BIOINF.LOCAL]<br>
> > (Mon May 30 17:18:05 2016) [[sssd[krb5_child[32832]]]]<br>
> [k5c_setup_fast]<br>
> > (0x0100): SSSD_KRB5_FAST_PRINCIPAL is set to<br>
> [host/lead.bioinf.local@BIOINF.LOCAL]<br>
> > (Mon May 30 17:18:05 2016) [[sssd[krb5_child[32832]]]]<br>
> > [check_fast_ccache] (0x0200): FAST TGT is still valid.<br>
> > (Mon May 30 17:18:05 2016) [[sssd[krb5_child[32832]]]] [become_user]<br>
> > (0x0200): Trying to become user [1713400053][1713400053].<br>
> > (Mon May 30 17:18:05 2016) [[sssd[krb5_child[32832]]]]<br>
> > [set_lifetime_options] (0x0100): SSSD_KRB5_RENEWABLE_LIFETIME is set to [7d]<br>
> > (Mon May 30 17:18:05 2016) [[sssd[krb5_child[32832]]]]<br>
> > [set_lifetime_options] (0x0100): SSSD_KRB5_LIFETIME is set to [1d]<br>
> > (Mon May 30 17:18:05 2016) [[sssd[krb5_child[32832]]]]<br>
> > [set_canonicalize_option] (0x0100): SSSD_KRB5_CANONICALIZE is set to [true]<br>
> > (Mon May 30 17:18:05 2016) [[sssd[krb5_child[32832]]]]<br>
> > [sss_krb5_prompter] (0x0020): Cannot handle password prompts.<br>
> > (Mon May 30 17:18:05 2016) [[sssd[krb5_child[32832]]]]<br>
> [k5c_send_data]<br>
> > (0x0200): Received error code 0<br>
> > 1.2 sssd_bioinf.local.log<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [check_ccache_files] (0x0200): Failed to check ccache file<br>
> > [KEYRING:persistent:1713400031].<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [check_ccache_files] (0x0200): Failed to check ccache file<br>
> > [KEYRING:persistent:1713400053].<br>
> > ...<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [check_and_export_options] (0x0100): No KDC explicitly configured, using<br>
> defaults.<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [check_and_export_options] (0x0100): No kpasswd server explicitly configured,<br>
> > using the KDC or defaults.<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [parse_krb5_map_user] (0x0200): Warning: krb5_map_user is empty!<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [load_backend_module] (0x0200): no module name found in confdb, using [ipa].<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [common_parse_search_base] (0x0100): Search base added:<br>
> > [SUDO][ou=SUDOers,dc=bioinf,dc=local][SUBTREE][]<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> [check_ipv4_addr]<br>
> > (0x0200): Loopback IPv4 address 127.0.0.1<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> [check_ipv6_addr]<br>
> > (0x0200): Loopback IPv6 address ::1<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [load_backend_module] (0x0200): no module name found in confdb, using [ipa].<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [common_parse_search_base] (0x0100): Search base added:<br>
> > [AUTOFS][cn=default,cn=automount,dc=bioinf,dc=local][SUBTREE][]<br>
> > (Mon May 30 17:16:01 2016) [sssd[be[bioinf.local]]]<br>
> > [load_backend_module] (0x0200): no module name found in confdb, using [ipa].<br>
> > ...<br>
> > (Mon May 30 17:16:11 2016) [sssd[be[bioinf.local]]]<br>
> > [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID<br>
> > from [(null)]<br>
> > (Mon May 30 17:16:11 2016) [sssd[be[bioinf.local]]]<br>
> > [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID<br>
> > from [(null)]<br>
> > (Mon May 30 17:16:11 2016) [sssd[be[bioinf.local]]]<br>
> > [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse<br>
> domain SID<br>
> > from [(null)]<br>
> > ...<br>
> > (Mon May 30 17:16:11 2016) [sssd[be[bioinf.local]]]<br>
> > [sdap_process_group_send] (0x0040): No Members. Done!<br>
> > (Mon May 30 17:16:11 2016) [sssd[be[bioinf.local]]]<br>
> > [sdap_process_group_send] (0x0040): No Members. Done!<br>
> > (Mon May 30 17:16:11 2016) [sssd[be[bioinf.local]]]<br>
> > [sdap_process_group_send] (0x0040): No Members. Done!<br>
> > ...<br>
> > 1.3 sssd_nss.log<br>
> > (Mon May 30 17:18:07 2016) [sssd[nss]] [calc_flat_name]<br>
> (0x0080): Flat<br>
> > name requested but domain has noflat name set, falling back to domain name<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [sss_cmd_get_version]<br>
> (0x0200):<br>
> > Received client version [1].<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [sss_cmd_get_version]<br>
> (0x0200):<br>
> > Offered version [1].<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [sss_cmd_get_version]<br>
> (0x0200):<br>
> > Received client version [1].<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [sss_cmd_get_version]<br>
> (0x0200):<br>
> > Offered version [1].<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [sss_parse_name_for_domains]<br>
> > (0x0200): name 'root' matched without domain, user is root<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [nss_cmd_getbynam] (0x0100):<br>
> > Requesting info for [root] from [<ALL>]<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [nss_cmd_initgroups_search]<br>
> > (0x0080): No matching domain found for [root], fail!<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [sss_parse_name_for_domains]<br>
> > (0x0200): name 'root' matched without domain, user is root<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [nss_cmd_getbynam] (0x0100):<br>
> > Requesting info for [root] from [<ALL>]<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [nss_cmd_initgroups_search]<br>
> > (0x0080): No matching domain found for [root], fail!<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [client_recv] (0x0200):<br>
> Client<br>
> > disconnected!<br>
> > (Mon May 30 17:20:01 2016) [sssd[nss]] [client_recv] (0x0200):<br>
> Client<br>
> > disconnected!<br>
> ><br>
> > 2 pki : catalina.2016-05-30.log<br>
> > May 30, 2016 2:18:10 PM org.apache.coyote.AbstractProtocol init<br>
> > SEVERE: Failed to initialize end point associated with ProtocolHandler<br>
> > ["http-bio-8443"]<br>
> > java.net.BindException: Could not bind to address: (-5982) Local Network<br>
> > address is in use. <null>:8443<br>
> > at org.apache.tomcat.util.net.JIoEndpoint.bind(JIoEndpoint.java:411)<br>
> > at<br>
> > org.apache.tomcat.util.net.AbstractEndpoint.init(AbstractEndpoint.java:640)<br>
> > at<br>
> org.apache.coyote.AbstractProtocol.init(AbstractProtocol.java:434)<br>
> > at<br>
> ><br>
> org.apache.coyote.http11.AbstractHttp11JsseProtocol.init(AbstractHttp11JsseProtocol.java:119)<br>
> > at<br>
> org.apache.catalina.connector.Connector.initInternal(Connector.java:978)<br>
> > at<br>
> org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:102)<br>
> > at<br>
> ><br>
> org.apache.catalina.core.StandardService.initInternal(StandardService.java:559)<br>
> > at<br>
> org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:102)<br>
> > at<br>
> > org.apache.catalina.core.StandardServer.initInternal(StandardServer.java:813)<br>
> > at<br>
> org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:102)<br>
> > at org.apache.catalina.startup.Catalina.load(Catalina.java:638)<br>
> > at org.apache.catalina.startup.Catalina.load(Catalina.java:663)<br>
> > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)<br>
> > at<br>
> > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)<br>
> > at<br>
> ><br>
> sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)<br>
> > at java.lang.reflect.Method.invoke(Method.java:497)<br>
> > at org.apache.catalina.startup.Bootstrap.load(Bootstrap.java:280)<br>
> > at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:454)<br>
> > Caused by: java.net.BindException: Could not bind to address:<br>
> (-5982) Local<br>
> > Network address is in use.<br>
> > at org.mozilla.jss.ssl.SocketBase.socketBind(Native Method)<br>
> > at<br>
> org.mozilla.jss.ssl.SSLServerSocket.<init>(SSLServerSocket.java:159)<br>
> > at<br>
> ><br>
> org.apache.tomcat.util.net.jss.JSSSocketFactory.createSocket(JSSSocketFactory.java:937)<br>
> > at<br>
> ><br>
> org.apache.tomcat.util.net.jss.JSSSocketFactory.createSocket(JSSSocketFactory.java:929)<br>
> > at<br>
> ><br>
> org.apache.tomcat.util.net.jss.JSSSocketFactory.createSocket(JSSSocketFactory.java:924)<br>
> > at org.apache.tomcat.util.net.JIoEndpoint.bind(JIoEndpoint.java:398)<br>
> > ... 17 more<br>
> > May 30, 2016 2:18:10 PM org.apache.catalina.core.StandardService<br>
> initInternal<br>
> > SEVERE: Failed to initialize connector [Connector[HTTP/1.1-8443]]<br>
> > org.apache.catalina.LifecycleException: Failed to initialize component<br>
> > [Connector[HTTP/1.1-8443]]<br>
> > at<br>
> org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:106)<br>
> > at<br>
> ><br>
> org.apache.catalina.core.StandardService.initInternal(StandardService.java:559)<br>
> > at<br>
> org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:102)<br>
> > at<br>
> > org.apache.catalina.core.StandardServer.initInternal(StandardServer.java:813)<br>
> > at<br>
> org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:102)<br>
> > at org.apache.catalina.startup.Catalina.load(Catalina.java:638)<br>
> > at org.apache.catalina.startup.Catalina.load(Catalina.java:663)<br>
> > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)<br>
> > at<br>
> > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)<br>
> > at<br>
> ><br>
> sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)<br>
> > at java.lang.reflect.Method.invoke(Method.java:497)<br>
> > at org.apache.catalina.startup.Bootstrap.load(Bootstrap.java:280)<br>
> > at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:454)<br>
> > Caused by: org.apache.catalina.LifecycleException: Protocol handler<br>
> > initialization failed<br>
> > at<br>
> org.apache.catalina.connector.Connector.initInternal(Connector.java:980)<br>
> > at<br>
> org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:102)<br>
> > ... 12 more<br>
> > Caused by: java.net.BindException: Could not bind to address:<br>
> (-5982) Local<br>
> > Network address is in use. <null>:8443<br>
> > at org.apache.tomcat.util.net.JIoEndpoint.bind(JIoEndpoint.java:411)<br>
> > at<br>
> > org.apache.tomcat.util.net.AbstractEndpoint.init(AbstractEndpoint.java:640)<br>
> > at<br>
> org.apache.coyote.AbstractProtocol.init(AbstractProtocol.java:434)<br>
> > at<br>
> ><br>
> org.apache.coyote.http11.AbstractHttp11JsseProtocol.init(AbstractHttp11JsseProtocol.java:119)<br>
> > at<br>
> org.apache.catalina.connector.Connector.initInternal(Connector.java:978)<br>
> > ... 13 more<br>
> > Caused by: java.net.BindException: Could not bind to address:<br>
> (-5982) Local<br>
> > Network address is in use.<br>
> > at org.mozilla.jss.ssl.SocketBase.socketBind(Native Method)<br>
> > at<br>
> org.mozilla.jss.ssl.SSLServerSocket.<init>(SSLServerSocket.java:159)<br>
> > at<br>
> ><br>
> org.apache.tomcat.util.net.jss.JSSSocketFactory.createSocket(JSSSocketFactory.java:937)<br>
> > at<br>
> ><br>
> org.apache.tomcat.util.net.jss.JSSSocketFactory.createSocket(JSSSocketFactory.java:929)<br>
> > at<br>
> ><br>
> org.apache.tomcat.util.net.jss.JSSSocketFactory.createSocket(JSSSocketFactory.java:924)<br>
> > at org.apache.tomcat.util.net.JIoEndpoint.bind(JIoEndpoint.java:398)<br>
> > ... 17 more<br>
> ><br>
> > 3. dirsrv<br>
> > [26/May/2016:12:14:10 +0200] - WARNING: userRoot: entry cache size<br>
> 512000B<br>
> > is less than db size 1163264B; We recommend to increase the entry cache size<br>
> > nsslapd-cachememsize.<br>
> > [26/May/2016:12:14:10 +0200] - WARNING: ipaca: entry cache size<br>
> 512000B is<br>
> > less than db size 1015808B; We recommend to increase the entry cache size<br>
> > nsslapd-cachememsize.<br>
> > [26/May/2016:12:14:10 +0200] - WARNING: changelog: entry cache size<br>
> 512000B<br>
> > is less than db size 10100736B; We recommend to increase the entry cache size<br>
> > nsslapd-cachememsize.<br>
> > [26/May/2016:12:14:10 +0200] schema-compat-plugin - scheduled<br>
> > schema-compat-plugin tree scan in about 5 seconds after the server startup!<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=dns,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=dns,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=keys,cn=sec,cn=dns,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=dns,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=dns,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=groups,cn=compat,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=computers,cn=compat,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=ng,cn=compat,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > ou=sudoers,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=users,cn=compat,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=vaults,cn=kra,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> > cn=ad,cn=etc,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> cn=casigningcert<br>
> > cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target<br>
> cn=casigningcert<br>
> > cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=bioinf,dc=local does not exist<br>
> > [26/May/2016:12:14:10 +0200] NSACLPlugin - The ACL target cn=automember<br>
> > rebuild membership,cn=tasks,cn=config does not exist<br>
> > [26/May/2016:12:14:10 +0200] - Skipping CoS Definition cn=Password<br>
> > Policy,cn=accounts,dc=bioinf,dc=local--no CoS Templates found, which<br>
> should be<br>
> > added before the CoS Definition.<br>
> > [26/May/2016:12:14:10 +0200] schema-compat-plugin - schema-compat-plugin<br>
> > tree scan will start in about 5 seconds!<br>
> > [26/May/2016:12:14:10 +0200] - slapd started. Listening on All<br>
> Interfaces<br>
> > port 389 for LDAP requests<br>
> > [26/May/2016:12:14:10 +0200] - Listening on All Interfaces port 636 for<br>
> > LDAPS requests<br>
> > [26/May/2016:12:14:10 +0200] - Listening on<br>
> > /var/run/slapd-BIOINF-LOCAL.socket for LDAPI requests<br>
> > [26/May/2016:12:14:15 +0200] schema-compat-plugin - warning: no<br>
> entries set<br>
> > up under ou=sudoers,dc=bioinf,dc=local<br>
> > [26/May/2016:12:14:15 +0200] schema-compat-plugin - warning: no<br>
> entries set<br>
> > up under cn=ng, cn=compat,dc=bioinf,dc=local<br>
> > [26/May/2016:12:14:15 +0200] schema-compat-plugin - Finished plugin<br>
> > initialization.<br>
> ><br>
> ><br>
> > On Mon, May 30, 2016 at 4:46 PM, Martin Kosek <<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a><br>
> <mailto:<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a>><br>
</div></div><div class="HOEnZb"><div class="h5">> > <mailto:<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a> <mailto:<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a>>>> wrote:<br>
> ><br>
> > On 05/30/2016 04:36 PM, Martin Basti wrote:<br>
> > ><br>
> > ><br>
> > > On 30.05.2016 14:20, seli irithyl wrote:<br>
> > >> Hi,<br>
> > >><br>
> > >> Since last update, I'am unable to log in to web ui with FF (e.g.<br>
> blank page)<br>
> > >> Any idea where too look for ?<br>
> > >><br>
> > >> Best regards,<br>
> > >><br>
> > >> Seli<br>
> > >><br>
> > >><br>
> > >><br>
> > >><br>
> > >><br>
> > > Hello,<br>
> > ><br>
> > > can you provide version of the freeIPA, firefox. Does it work from<br>
> different<br>
> > > browser? does it work from private mode?<br>
> ><br>
> > + does [CTRL]+F5 helps? Do advise in<br>
> > <a href="http://www.freeipa.org/page/Troubleshooting#Web_UI" rel="noreferrer" target="_blank">http://www.freeipa.org/page/Troubleshooting#Web_UI</a><br>
> > help?<br>
> ><br>
> ><br>
><br>
><br>
><br>
><br>
<br>
<br>
</div></div><span class="HOEnZb"><font color="#888888">--<br>
Petr Vobornik<br>
</font></span></blockquote></div><br></div>