<html><body><p>Thanks Petr,<br><br> Since the last recycle of the Host hosting the First Master it has been stable for about a week now. Only thing I did was to spread out my replication agreements. I had 8 replications hitting it but now have 4 going to it and the other 4 to its backup replica with the first master and the backup replica having an agreement. <br><br><br>Not sure that fixed it or not but it seems to be stable at this point and I know the docs say no more than 4 replications agreements so maybe it was the cause. <br><br><br><br><br>Sean Hogan<br><br><br><br><br><br><img width="16" height="16" src="cid:2__=88BBF573DFF7BBF08f9e8a93df938690918c88B@" border="0" alt="Inactive hide details for Petr Spacek ---06/28/2016 10:24:01 AM---On 22.6.2016 23:09, Sean Hogan wrote: > SLAPD showing"><font color="#424282">Petr Spacek ---06/28/2016 10:24:01 AM---On 22.6.2016 23:09, Sean Hogan wrote: > SLAPD showing</font><br><br><font size="2" color="#5F5F5F">From: </font><font size="2">Petr Spacek <pspacek@redhat.com></font><br><font size="2" color="#5F5F5F">To: </font><font size="2">Sean Hogan/Durham/IBM@IBMUS</font><br><font size="2" color="#5F5F5F">Cc: </font><font size="2">freeipa-users@redhat.com</font><br><font size="2" color="#5F5F5F">Date: </font><font size="2">06/28/2016 10:24 AM</font><br><font size="2" color="#5F5F5F">Subject: </font><font size="2">Re: [Freeipa-users] IPA 3.0.47 to 3.0.50 Upgrade problem</font><br><hr width="100%" size="2" align="left" noshade style="color:#8091A5; "><br><br><br><tt>On 22.6.2016 23:09, Sean Hogan wrote:<br>> SLAPD showing<br>> <br>> 22/Jun/2016:17:01:59 -0400] slapi_ldap_bind - Error: could not perform<br>> interactive bind for id [] mech [GSSAPI]: error 49 (Invalid credentials)<br>> [22/Jun/2016:17:06:59 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error 49<br>> (Invalid credentials) (SASL(-13): authentication failure: GSSAPI Failure:<br>> gss_accept_sec_context) errno 0 (Success)<br>> <br>> <br>> where would these creds be and what ID? I am using SASL so I assume it to<br>> be sasl_user DNS/FirstMaster.watson.local or something like that?<br><br>These are in /etc/dirsrv/ds.keytab.<br><br>I would start with<br># klist -kt /etc/dirsrv/ds.keytab<br>and try to proceed with kinit etc. (very similarly to the bind-dyndb-ldap how-to).<br><br>I hope it helps.<br><br>Petr^2 Spacek<br><br><br>> From: Sean Hogan/Durham/IBM@IBMUS<br>> To: Petr Spacek <pspacek@redhat.com><br>> Cc: freeipa-users@redhat.com<br>> Date: 06/22/2016 08:36 AM<br>> Subject: Re: [Freeipa-users] IPA 3.0.47 to 3.0.50 Upgrade problem<br>> Sent by: freeipa-users-bounces@redhat.com<br>> <br>> <br>> <br>> Hi Peter...<br>> <br>> Yes..... this has me doing loops in my head to /dev/null<br>> <br>> You are correct I could not complete the BIND steps... I did them yesterday<br>> but did not post results as I wanted to stop bugging you all :)<br>> The initial credential section of that I could not complete nor can I get<br>> an keytab without it and I don't think I have an issue with cert versions<br>> (used the SASL section). The upgrade log from 3.47 to 3.50 on this one<br>> server did show an error with named though.<br>> <br>> I had the box powered down again last night after testing the BIND<br>> procedures... and its been up since then. Which makes we really not sure<br>> what is going on(DNS DOS from internal maybe? I get a lot of outside<br>> requests showing network unreachable and I don't forward to a outside DNS).<br>> If it was a password/cert/cipher/file perm issue then I don't see how it<br>> can work at all after a reboot.<br>> <br>> I am thinking it needs a rebuild.. I have not done this on a First Master<br>> IPA is there anything I need to be take into consider with it being first<br>> master? Right now I have 8 IPAs all DNS, NTP and CAs on differ vlans but<br>> the first master is the fail back IPA(on the only vlan that can talk to the<br>> others) in case there local vlan IPA dies. First Master is also the master<br>> CA in the realm where everything is enrolled to originally. We then mod<br>> everything to point to the vlan IPA with the Firstmaster as secondary with<br>> our vlan-specific scripts we run after ipa client install.<br>> <br>> With the box rebooted last night I am now getting normal functionality but<br>> it prob wont last long as indicated from the past...<br>> <br>> Working<br>> [bob@FirstMaster ~]# kinit admin<br>> Password for admin@DOMAIN.LOCAL:<br>> Warning: Your password will expire in 6 days on Tue Jun 28 14:55:52 2016<br>> [bob@FirstMaster ~]#<br>> <br>> I did post ldap logs in my first email though... will readd them to this<br>> and when it dies off again I will add more.<br>> <br>> <br>>> [20/Jun/2016:13:59:00 -0400] - Detected Disorderly Shutdown last time<br>>> Directory Server was running, recovering database.<br>>> [20/Jun/2016:13:59:01 -0400] schema-compat-plugin - warning: no entries<br>> set<br>>> up under cn=computers, cn=compat,dc=domain,dc=local<br>>> [20/Jun/2016:13:59:48 -0400] NSMMReplicationPlugin - ruv_compare_ruv: RUV<br>>> [database RUV] does not contain element [{replica 7} 55ca26a0000900070000<br>>> 5688d8e6001000070000] which is present in RUV [changelog max RUV]<br>>> [20/Jun/2016:13:59:48 -0400] NSMMReplicationPlugin -<br>>> replica_check_for_data_reload: Warning: for replica dc=domain,dc=local<br>>> there were some differences between the changelog max RUV and the<br>> database<br>>> RUV. If there are obsolete elements in the database RUV, you should<br>> remove<br>>> them using the CLEANALLRUV task. If they are not obsolete, you should<br>> check<br>>> their status to see why there are no changes from those servers in the<br>>> changelog.<br>>> [20/Jun/2016:13:59:48 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:59:48 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:59:48 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:59:48 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:48 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:48 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:48 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:48 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver9.domain.local" (server9:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:59:48 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:59:48 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver8.domain.local" (server8:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:59:48 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:48 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:48 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meTobldvxl0011.domain.local" (1server:389): Replication bind<br>> with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:59:48 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:48 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:48 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver3.domain.local" (server3:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:59:48 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:59:48 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:59:48 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:48 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:48 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver7.domain.local" (server7:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:59:48 -0400] - slapd started. Listening on All Interfaces<br>>> port 389 for LDAP requests<br>>> [20/Jun/2016:13:59:48 -0400] - Listening on All Interfaces port 636 for<br>>> LDAPS requests<br>>> [20/Jun/2016:13:59:48 -0400] - Listening<br>>> on /var/run/slapd-DOMAIN-LOCAL.socket for LDAPI requests<br>>> [20/Jun/2016:13:59:48 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:48 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:48 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver4.domain.local" (server4:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:59:48 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:59:48 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 0 (Success)<br>>> [20/Jun/2016:13:59:48 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:48 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver2.domain.local" (server2:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:59:51 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver8.domain.local" (server8:389): Replication bind with<br>>> GSSAPI auth resumed<br>>> [20/Jun/2016:13:59:51 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error 49<br>>> (Invalid credentials) (SASL(-13): authentication failure: GSSAPI Failure:<br>>> gss_accept_sec_context) errno 0 (Success)<br>>> [20/Jun/2016:13:59:51 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error 49 (Invalid credentials)<br>>> [20/Jun/2016:13:59:51 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver3.domain.local" (server3:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error 49 (Invalid credentials) (SASL(-13):<br>>> authentication failure: GSSAPI Failure: gss_accept_sec_context)<br>>> [20/Jun/2016:13:59:51 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (No credentials cache<br>>> found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:51 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:51 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (No credentials cache<br>>> found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:51 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:51 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (No credentials cache<br>>> found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:51 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:51 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (No credentials cache<br>>> found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:51 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:51 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (No credentials cache<br>>> found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:59:51 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:59:57 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error 49<br>>> (Invalid credentials) (SASL(-13): authentication failure: GSSAPI Failure:<br>>> gss_accept_sec_context) errno 0 (Success)<br>>> [20/Jun/2016:13:59:57 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error 49 (Invalid credentials)<br>>> [20/Jun/2016:13:59:57 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver2.domain.local" (server2:389): Replication bind with<br>>> GSSAPI auth resumed<br>> <br>> <br>> <br>> Sean Hogan<br>> <br>> <br>> <br>> <br>> <br>> Inactive hide details for Petr Spacek ---06/21/2016 10:20:43 PM---On<br>> 22.6.2016 02:56, Sean Hogan wrote: > More infoPetr Spacek ---06/21/2016<br>> 10:20:43 PM---On 22.6.2016 02:56, Sean Hogan wrote: > More info<br>> <br>> From: Petr Spacek <pspacek@redhat.com><br>> To: freeipa-users@redhat.com<br>> Date: 06/21/2016 10:20 PM<br>> Subject: Re: [Freeipa-users] IPA 3.0.47 to 3.0.50 Upgrade problem<br>> Sent by: freeipa-users-bounces@redhat.com<br>> <br>> <br>> <br>> On 22.6.2016 02:56, Sean Hogan wrote:<br>>> More info<br>>><br>>><br>>> Krb5 log is showing:<br>>> Jun 21 20:42:47 Firstmaster.domain.local krb5kdc[2141](info): AS_REQ (4<br>>> etypes {18 17 16 23}) 10.x.x.x: LOOKING_UP_CLIENT: admin@domain.LOCAL for<br>>> krbtgt/DOMAIN.LOCAL@DOMAIN.LOCAL, Server error<br>> <br>> <br>> Hello,<br>> <br>> this is really fishy. I would bet that there is a problem with LDAP server<br>> and<br>> DNS errors are just consequence of it.<br>> <br>> I suspect that you will not be able to finish steps mentioned in<br>> </tt><tt><a href="https://fedorahosted.org/bind-dyndb-ldap/wiki/BIND9/NamedCannotStart#a3.FailedtoinitcredentialsorFailedtogetinitialcredentialsDecryptintegritycheckfailedorClientscredentialshavebeenrevoked">https://fedorahosted.org/bind-dyndb-ldap/wiki/BIND9/NamedCannotStart#a3.FailedtoinitcredentialsorFailedtogetinitialcredentialsDecryptintegritycheckfailedorClientscredentialshavebeenrevoked</a></tt><tt><br>> <br>> <br>> If it is the case I would turn your attention to krb5kdc.log and LDAP<br>> server<br>> logs in /var/log/dirsrv/*<br>> <br>> There must be something wrong with the LDAP server.<br>> <br>> Petr^2 Spacek<br>> <br>> <br>>><br>>> [bob@Firstmaster etc]# kinit -v admin<br>>> kinit: Credentials cache file '/tmp/krb5cc_0' not found while validating<br>>> credentials<br>>><br>>><br>>><br>>><br>>><br>>><br>>> Sean Hogan<br>>><br>>><br>>><br>>><br>>><br>>><br>>> From: Sean Hogan/Durham/IBM<br>>> To: freeipa-users <freeipa-users@redhat.com><br>>> Date: 06/21/2016 12:02 PM<br>>> Subject: Re: [Freeipa-users] IPA 3.0.47 to 3.0.50 Upgrade problem<br>>><br>>><br>>> Has anyone seen these before?<br>>><br>>><br>>><br>>> First Master IPA DNS logs show: Looks like the host names are getting<br>> the<br>>> domain twice domain.local.domain.local<br>>><br>>><br>>> client 10.x.x.x#58094: query failed (SERVFAIL) for<br>>> server1.domain.local.domain.local/IN/AAAA at query.c:6569<br>>> timeout in ldap_pool_getconnection(): try to raise 'connections'<br>> parameter;<br>>> potential deadlock?<br>>> client 10.x.x.x#44147: query failed (SERVFAIL) for<br>>> x.x.x.10.in-addr.arpa/IN/PTR at query.c:6569<br>>> timeout in ldap_pool_getconnection(): try to raise 'connections'<br>> parameter;<br>>> potential deadlock?<br>>> client 10.x.x.x#56466: query failed (SERVFAIL) for<br>>> x.x.x.10.in-addr.arpa/IN/PTR at query.c:6569<br>>> timeout in ldap_pool_getconnection(): try to raise 'connections'<br>> parameter;<br>>> potential deadlock?<br>>> client 10.x.x.x53367: query failed (SERVFAIL) for<br>>> server2.domain.local.domain.local/IN/A at query.c:6569<br>>> timeout in ldap_pool_getconnection(): try to raise 'connections'<br>> parameter;<br>>> potential deadlock?<br>>> client 10.x.x.x#53367: query failed (SERVFAIL) for<br>>> server2.domain.local.domain.local/IN/AAAA at query.c:6569<br>>><br>>><br>>><br>>> So enrolls are failing at this point when tyring to enroll to a replica:<br>>><br>>> [bob@server1 log]# ipa-client-install –enable-dns-updates<br>>> Discovery was successful!<br>>> Hostname: server1.watson.local<br>>> Realm: DOMAIN.LOCAL<br>>> DNS Domain: domain.local<br>>> IPA Server: ipareplica.domain.local<br>>> BaseDN: dc=domain,dc=local<br>>><br>>> Continue to configure the system with these values? [no]: yes<br>>> User authorized to enroll computers: bob<br>>> Synchronizing time with KDC...<br>>> Password for bob@DOMAIN.LOCAL:<br>>> Successfully retrieved CA cert<br>>> Subject: CN=Certificate Authority,O=DOMAIN.LOCAL<br>>> Issuer: CN=Certificate Authority,O=DOMAIN.LOCAL<br>>> Valid From: Tue Jan 06 19:37:09 2015 UTC<br>>> Valid Until: Sat Jan 06 19:37:09 2035 UTC<br>>><br>>> Enrolled in IPA realm DOMAIN.LOCAL<br>>> Attempting to get host TGT...<br>>> Created /etc/ipa/default.conf<br>>> New SSSD config will be created<br>>> Configured sudoers in /etc/nsswitch.conf<br>>> Configured /etc/sssd/sssd.conf<br>>> Configured /etc/krb5.conf for IPA realm DOMAIN.LOCAL<br>>> trying </tt><tt><a href="https://ipareplica.domain.local/ipa/xml">https://ipareplica.domain.local/ipa/xml</a></tt><tt><br>>> Cannot connect to the server due to Kerberos error: Kerberos error:<br>>> Kerberos error: ('Unspecified GSS failure. Minor code may provide more<br>>> information', 851968)/('KDC returned error string: PROCESS_TGS',<br>>> -1765328324)/. Trying with delegate=True<br>>> trying </tt><tt><a href="https://ipareplica.domain.local/ipa/xml">https://ipareplica.domain.local/ipa/xml</a></tt><tt><br>>> Second connect with delegate=True also failed: Kerberos error: Kerberos<br>>> error: ('Unspecified GSS failure. Minor code may provide more<br>>> information', 851968)/('KDC returned error string: PROCESS_TGS',<br>>> -1765328324)/<br>>> Cannot connect to the IPA server XML-RPC interface: Kerberos error:<br>>> Kerberos error: ('Unspecified GSS failure. Minor code may provide more<br>>> information', 851968)/('KDC returned error string: PROCESS_TGS',<br>>> -1765328324)/<br>>> Installation failed. Rolling back changes.<br>>> Unenrolling client from IPA server<br>>> Unenrolling host failed: Error obtaining initial credentials: Generic<br>> error<br>>> (see e-text).<br>>><br>>> Removing Kerberos service principals from /etc/krb5.keytab<br>>> Disabling client Kerberos and LDAP configurations<br>>> Redundant SSSD configuration file /etc/sssd/sssd.conf was moved<br>>> to /etc/sssd/sssd.conf.deleted<br>>> Restoring client configuration files<br>>> nscd daemon is not installed, skip configuration<br>>> nslcd daemon is not installed, skip configuration<br>>> Client uninstall complete.<br>>><br>>><br>>> Sean Hogan<br>>><br>>><br>>><br>>><br>>><br>>><br>>><br>>><br>>> From: Sean Hogan/Durham/IBM<br>>> To: Sean Hogan/Durham/IBM@IBMUS<br>>> Cc: freeipa-users <freeipa-users@redhat.com><br>>> Date: 06/20/2016 12:49 PM<br>>> Subject: Re: [Freeipa-users] IPA 3.0.47 to 3.0.50 Upgrade problem<br>>><br>>><br>>> Also seeing this in the upgrade log on the first master but not on the 7<br>>> ipas.<br>>><br>>> ERROR Failed to restart named: Command '/sbin/service named restart '<br>>> returned non-zero exit status 7<br>>><br>>><br>>> which led me to<br>>><br>>> </tt><tt><a href="https://bugzilla.redhat.com/show_bug.cgi?id=895298">https://bugzilla.redhat.com/show_bug.cgi?id=895298</a></tt><tt><br>>><br>>><br>>><br>>><br>>><br>>> Sean Hogan<br>>><br>>><br>>><br>>><br>>><br>>><br>>><br>>> From: Sean Hogan/Durham/IBM@IBMUS<br>>> To: freeipa-users <freeipa-users@redhat.com><br>>> Date: 06/20/2016 11:46 AM<br>>> Subject: Re: [Freeipa-users] IPA 3.0.47 to 3.0.50 Upgrade problem<br>>> Sent by: freeipa-users-bounces@redhat.com<br>>><br>>><br>>><br>>> Hi All..<br>>><br>>> I thought we fixed this issue by rebooting the KVM host but it is showing<br>>> again. Our First Master IPA is being rebooted 2 -5 times a day now just<br>> to<br>>> keep it alive.<br>>><br>>> What we are seeing:<br>>><br>>> God@FirstMaster log]# kinit admin<br>>> kinit: Cannot contact any KDC for realm 'Domain.LOCAL' while getting<br>>> initial credentials<br>>><br>>> DNS is not working as nslookup is failing to a replica.... think once we<br>>> lose DNS it all goes down hill which makes sense.<br>>><br>>> [god@FirstMaster log]# ipactl stop -----> Just hangs forever.. no<br>> replies..<br>>> no error.. nothing<br>>><br>>> I try service named stop and nothing happens<br>>><br>>> I have the box hard shutdown from KVM console. Reboot it and it works for<br>> a<br>>> little while but eventually back to same behavior.<br>>><br>>> At this point I can service named stop and it responds... ipactl status<br>> and<br>>> it responds.. but when if I try service named restart I get<br>>><br>>> [god@FirstMaster log]# service named stop<br>>> Stopping named: ......<br>>><br>>> [god@Firstmaster log]# service named start<br>>> Starting named: [FAILED]<br>>><br>>> [god@FirstMaster log]# service named status<br>>> rndc: connect failed: 127.0.0.1#953: connection refused<br>>> named dead but pid file exists<br>>><br>>> Rebooted box and it is hung on shutting down domain-local and never fully<br>>> shuts down.. have to get it hard shutdown again.<br>>> During an attempt to gracefully shut down we see this<br>>><br>>> Shutting Down dirsrv:<br>>> PKI-IPA OK<br>>> DOMAIN-LOCAL FAILED<br>>> *** Error: 1 instance(s) unsuccessfully stopped FAILED<br>>><br>>> Then it moves on to shut other things down and returns to dirsrv<br>>> Shutting Down dirsrv:<br>>> PKI-IPA....server already stopped FAILED {Makes sense.. it died earlier}<br>>> DOMAIN-LOCAL... {this sits here til we hard shutdown}<br>>><br>>><br>>><br>>> bind-libs-9.8.2-0.47.rc1.el6.x86_64<br>>> bind-9.8.2-0.47.rc1.el6.x86_64<br>>> bind-utils-9.8.2-0.47.rc1.el6.x86_64<br>>><br>>><br>>> ipa-client-3.0.0-50.el6.1.x86_64<br>>> ipa-server-selinux-3.0.0-50.el6.1.x86_64<br>>> ipa-server-3.0.0-50.el6.1.x86_64<br>>> sssd-ipa-1.13.3-22.el6.x86_64<br>>><br>>><br>>> /var/log/dirsrv/slapd-DOMAIN-LOCAL<br>>> [20/Jun/2016:13:29:06 -0400] - 389-Directory/1.2.11.15 B2016.063.2110<br>>> starting up<br>>> [20/Jun/2016:13:29:06 -0400] schema-compat-plugin - warning: no entries<br>> set<br>>> up under cn=computers, cn=compat,dc=domain,dc=local<br>>> [20/Jun/2016:13:29:07 -0400] NSMMReplicationPlugin - ruv_compare_ruv: RUV<br>>> [database RUV] does not contain element [{replica 7} 55ca26a0000900070000<br>>> 5688d8e6001000070000] which is present in RUV [changelog max RUV]<br>>> [20/Jun/2016:13:29:07 -0400] NSMMReplicationPlugin -<br>>> replica_check_for_data_reload: Warning: for replica dc=domain,dc=local<br>>> there were some differences between the changelog max RUV and the<br>> database<br>>> RUV. If there are obsolete elements in the database RUV, you should<br>> remove<br>>> them using the CLEANALLRUV task. If they are not obsolete, you should<br>> check<br>>> their status to see why there are no changes from those servers in the<br>>> changelog.<br>>> [20/Jun/2016:13:29:07 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:29:07 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:29:07 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:29:07 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:29:07 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:29:07 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver8.domain.local" (server8:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:29:07 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC</tt><br><tt>>> for requested realm)<br>>> [20/Jun/2016:13:29:07 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:29:07 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:29:07 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver9.domain.local" (server9:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:29:07 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:29:07 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:29:07 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:29:07 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver3.domain.local" (server3:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:29:07 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:29:07 -0400] - slapd started. Listening on All Interfaces<br>>> port 389 for LDAP requests<br>>> [20/Jun/2016:13:29:07 -0400] - Listening on All Interfaces port 636 for<br>>> LDAPS requests<br>>> [20/Jun/2016:13:29:07 -0400] - Listening<br>>> on /var/run/slapd-DOMAIN-LOCAL.socket for LDAPI requests<br>>> [20/Jun/2016:13:29:07 -0400] set_krb5_creds - Could not get initial<br>>> credentials for principal [ldap/server1.domain.local@DOMAIN.LOCAL] in<br>>> keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC<br>>> for requested realm)<br>>> [20/Jun/2016:13:29:07 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:29:07 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:29:07 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver4.domain.local" (server4:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:29:07 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:29:07 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:29:07 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meTo1server.domain.local" (1server:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:29:07 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 2 (No such file or directory)<br>>> [20/Jun/2016:13:29:07 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:29:07 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver7.domain.local" (server7:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:29:07 -0400] slapd_ldap_sasl_interactive_bind - Error:<br>>> could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2<br>>> (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS<br>>> failure. Minor code may provide more information (Credentials cache file<br>>> '/tmp/krb5cc_495' not found)) errno 0 (Success)<br>>> [20/Jun/2016:13:29:07 -0400] slapi_ldap_bind - Error: could not perform<br>>> interactive bind for id [] mech [GSSAPI]: error -2 (Local error)<br>>> [20/Jun/2016:13:29:07 -0400] NSMMReplicationPlugin -<br>>> agmt="cn=meToserver2.domain.local" (server2:389): Replication bind with<br>>> GSSAPI auth failed: LDAP error -2 (Local error) (SASL(-1): generic<br>> failure:<br>>> GSSAPI Error: Unspecified GSS failure. Minor code may provide more<br>>> information (Credentials cache file '/tmp/krb5cc_495' not found))<br>>> [20/Jun/2016:13:29:10 -0400] NSMMReplicationPlugin -<br>> <br><br><br>-- <br>Petr Spacek @ Red Hat<br><br></tt><br><br><BR>
</body></html>