<div dir="ltr"><div><div><div><div><div><div><div>Hi Florence.<br><br></div>Thanks for your support.<br><br></div>Yes, httpd is using /etc/httpd/alias as NSS DB. And seems that all permissions and certificates are good:<br><i>[root@mlv-ipa01 ~]# ls -l /etc/httpd/alias/<br>total 184<br>-r--r--r-- 1 root root 1345 Sep 7 2015 cacert.asc<br>-rw-rw---- 1 root apache 65536 Nov 17 11:06 cert8.db<br>-rw-r-----. 1 root apache 65536 Sep 4 2015 cert8.db.orig<br>-rw-------. 1 root root 4833 Sep 4 2015 install.log<br>-rw-rw---- 1 root apache 16384 Nov 17 11:06 key3.db<br>-rw-r-----. 1 root apache 16384 Sep 4 2015 key3.db.orig<br>lrwxrwxrwx 1 root root 24 Nov 17 10:24 libnssckbi.so -> /usr/lib64/libnssckbi.so<br>-rw-rw---- 1 root apache 20 Sep 7 2015 pwdfile.txt<br>-rw-rw---- 1 root apache 16384 Sep 7 2015 secmod.db<br>-rw-r-----. 1 root apache 16384 Sep 4 2015 secmod.db.orig</i><br><br></div>And password validations seems ok, too:<br><i>[root@mlv-ipa01 ~]# certutil -K -d /etc/httpd/alias/ -f /etc/httpd/alias/pwdfile.txt<br>certutil: Checking token "NSS Certificate DB" in slot "NSS User Private Key and Certificate Services"<br>< 0> rsa **************************************** NSS Certificate DB:Server-Cert<br>< 1> rsa **************************************** NSS Certificate DB:Signing-Cert<br>< 2> rsa **************************************** NSS Certificate DB:ipaCert</i><br><br></div>Enabling mod-nss debug I can see these logs:<br><i>[root@mlv-ipa01 ~]# tail -f /var/log/httpd/error_log<br>[Thu Nov 17 15:05:10.807603 2016] [suexec:notice] [pid 10660] AH01232: suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)<br>[Thu Nov 17 15:05:10.807958 2016] [:warn] [pid 10660] NSSSessionCacheTimeout is deprecated. Ignoring.<br>[Thu Nov 17 15:05:10.807991 2016] [:debug] [pid 10660] nss_engine_init.c(454): SNI: <a href="http://mlv-ipa01.ipa.mydomain.com">mlv-ipa01.ipa.mydomain.com</a> -> Server-Cert<br>[Thu Nov 17 15:05:11.002664 2016] [:info] [pid 10660] Configuring server for SSL protocol<br>[Thu Nov 17 15:05:11.002817 2016] [:debug] [pid 10660] nss_engine_init.c(770): NSSProtocol: Enabling TLSv1.0<br>[Thu Nov 17 15:05:11.002838 2016] [:debug] [pid 10660] nss_engine_init.c(775): NSSProtocol: Enabling TLSv1.1<br>[Thu Nov 17 15:05:11.002847 2016] [:debug] [pid 10660] nss_engine_init.c(780): NSSProtocol: Enabling TLSv1.2<br>[Thu Nov 17 15:05:11.002856 2016] [:debug] [pid 10660] nss_engine_init.c(839): NSSProtocol: [TLS 1.0] (minimum)<br>[Thu Nov 17 15:05:11.002876 2016] [:debug] [pid 10660] nss_engine_init.c(866): NSSProtocol: [TLS 1.2] (maximum)<br>[Thu Nov 17 15:05:11.003099 2016] [:debug] [pid 10660] nss_engine_init.c(906): Disabling TLS Session Tickets<br>[Thu Nov 17 15:05:11.003198 2016] [:debug] [pid 10660] nss_engine_init.c(916): Enabling DHE key exchange<br>[Thu Nov 17 15:05:11.003313 2016] [:debug] [pid 10660] nss_engine_init.c(1077): NSSCipherSuite: Configuring permitted SSL ciphers [+aes_128_sha_256,+aes_256_sha_256,+ecdhe_ecdsa_aes_128_gcm_sha_256,+ecdhe_ecdsa_aes_128_sha,+ecdhe_ecdsa_aes_256_gcm_sha_384,+ecdhe_ecdsa_aes_256_sha,+ecdhe_rsa_aes_128_gcm_sha_256,+ecdhe_rsa_aes_128_sha,+ecdhe_rsa_aes_256_gcm_sha_384,+ecdhe_rsa_aes_256_sha,+rsa_aes_128_gcm_sha_256,+rsa_aes_128_sha,+rsa_aes_256_gcm_sha_384,+rsa_aes_256_sha]<br>[Thu Nov 17 15:05:11.003469 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_null_md5<br>[Thu Nov 17 15:05:11.003483 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_null_sha<br>[Thu Nov 17 15:05:11.003491 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_rc4_40_md5<br>[Thu Nov 17 15:05:11.003509 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_rc4_128_md5<br>[Thu Nov 17 15:05:11.003632 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_rc4_128_sha<br>[Thu Nov 17 15:05:11.003740 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_rc2_40_md5<br>[Thu Nov 17 15:05:11.003747 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_des_sha<br>[Thu Nov 17 15:05:11.003802 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_3des_sha<br>[Thu Nov 17 15:05:11.003902 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_des_sha<br>[Thu Nov 17 15:05:11.004001 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: rsa_aes_128_sha<br>[Thu Nov 17 15:05:11.004167 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: rsa_aes_256_sha<br>[Thu Nov 17 15:05:11.004180 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: null_sha_256<br>[Thu Nov 17 15:05:11.004191 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: aes_128_sha_256<br>[Thu Nov 17 15:05:11.004285 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: aes_256_sha_256<br>[Thu Nov 17 15:05:11.004352 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: camelia_128_sha<br>[Thu Nov 17 15:05:11.004437 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_des_56_sha<br>[Thu Nov 17 15:05:11.004509 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: rsa_rc4_56_sha<br>[Thu Nov 17 15:05:11.004606 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: camelia_256_sha<br>[Thu Nov 17 15:05:11.004668 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: rsa_aes_128_gcm_sha_256<br>[Thu Nov 17 15:05:11.004724 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: rsa_aes_256_gcm_sha_384<br>[Thu Nov 17 15:05:11.004806 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: fips_3des_sha<br>[Thu Nov 17 15:05:11.004881 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: fips_des_sha<br>[Thu Nov 17 15:05:11.004956 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_3des_sha<br>[Thu Nov 17 15:05:11.005027 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_aes_128_sha<br>[Thu Nov 17 15:05:11.005106 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_aes_256_sha<br>[Thu Nov 17 15:05:11.005173 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_camellia_128_sha<br>[Thu Nov 17 15:05:11.005238 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_camellia_256_sha<br>[Thu Nov 17 15:05:11.005309 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_aes_128_sha256<br>[Thu Nov 17 15:05:11.005380 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_aes_256_sha256<br>[Thu Nov 17 15:05:11.005452 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_aes_128_gcm_sha_256<br>[Thu Nov 17 15:05:11.005524 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: dhe_rsa_aes_256_gcm_sha_384<br>[Thu Nov 17 15:05:11.005596 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_ecdsa_null_sha<br>[Thu Nov 17 15:05:11.005655 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_ecdsa_rc4_128_sha<br>[Thu Nov 17 15:05:11.005698 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_ecdsa_3des_sha<br>[Thu Nov 17 15:05:11.005814 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_ecdsa_aes_128_sha<br>[Thu Nov 17 15:05:11.005859 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_ecdsa_aes_256_sha<br>[Thu Nov 17 15:05:11.005904 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_ecdsa_null_sha<br>[Thu Nov 17 15:05:11.005948 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_ecdsa_rc4_128_sha<br>[Thu Nov 17 15:05:11.005993 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_ecdsa_3des_sha<br>[Thu Nov 17 15:05:11.006037 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: ecdhe_ecdsa_aes_128_sha<br>[Thu Nov 17 15:05:11.006081 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: ecdhe_ecdsa_aes_256_sha<br>[Thu Nov 17 15:05:11.006124 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_rsa_null_sha<br>[Thu Nov 17 15:05:11.006181 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_rsa_128_sha<br>[Thu Nov 17 15:05:11.006223 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_rsa_3des_sha<br>[Thu Nov 17 15:05:11.006261 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_rsa_aes_128_sha<br>[Thu Nov 17 15:05:11.006304 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_rsa_aes_256_sha<br>[Thu Nov 17 15:05:11.006348 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_rsa_null<br>[Thu Nov 17 15:05:11.006391 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_rsa_rc4_128_sha<br>[Thu Nov 17 15:05:11.006428 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_rsa_3des_sha<br>[Thu Nov 17 15:05:11.006466 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: ecdhe_rsa_aes_128_sha<br>[Thu Nov 17 15:05:11.006503 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: ecdhe_rsa_aes_256_sha<br>[Thu Nov 17 15:05:11.006541 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_anon_null_sha<br>[Thu Nov 17 15:05:11.006580 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_anon_rc4_128sha<br>[Thu Nov 17 15:05:11.006622 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_anon_3des_sha<br>[Thu Nov 17 15:05:11.006649 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_anon_aes_128_sha<br>[Thu Nov 17 15:05:11.006682 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdh_anon_aes_256_sha<br>[Thu Nov 17 15:05:11.006725 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_ecdsa_aes_128_sha_256<br>[Thu Nov 17 15:05:11.006730 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_rsa_aes_128_sha_256<br>[Thu Nov 17 15:05:11.006734 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: ecdhe_ecdsa_aes_128_gcm_sha_256<br>[Thu Nov 17 15:05:11.006737 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_ecdsa_aes_256_sha_384<br>[Thu Nov 17 15:05:11.006740 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Disable cipher: ecdhe_rsa_aes_256_sha_384<br>[Thu Nov 17 15:05:11.006743 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: ecdhe_ecdsa_aes_256_gcm_sha_384<br>[Thu Nov 17 15:05:11.006746 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: ecdhe_rsa_aes_256_gcm_sha_384<br>[Thu Nov 17 15:05:11.006749 2016] [:debug] [pid 10660] nss_engine_init.c(1140): Enable cipher: ecdhe_rsa_aes_128_gcm_sha_256<br>[Thu Nov 17 15:05:11.006759 2016] [:info] [pid 10660] Using nickname Server-Cert.<br>[Thu Nov 17 15:05:11.006771 2016] [:error] [pid 10660] Certificate not found: 'Server-Cert'<br><br>[root@mlv-ipa01 ~]# tail -f /var/log/messages<br>Nov 17 15:05:04 mlv-ipa01 systemd[1]: Starting Identity, Policy, Audit...<br>Nov 17 15:05:07 mlv-ipa01 ipactl: Existing service file detected!<br>Nov 17 15:05:07 mlv-ipa01 ipactl: Assuming stale, cleaning and proceeding<br>Nov 17 15:05:07 mlv-ipa01 systemd[1]: Starting 389 Directory Server IPA-MYDOMAIN-COM....<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.799208210 +0100] SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password.<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.803853873 +0100] SSL alert: Security Initialization: Enabling default cipher set.<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.805145890 +0100] SSL alert: Configured NSS Ciphers<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.806316182 +0100] SSL alert: #011TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.807723387 +0100] SSL alert: #011TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.808923825 +0100] SSL alert: #011TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.810155882 +0100] SSL alert: #011TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.811325853 +0100] SSL alert: #011TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.812784224 +0100] SSL alert: #011TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.813976726 +0100] SSL alert: #011TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.815120447 +0100] SSL alert: #011TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.816327755 +0100] SSL alert: #011TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.817977411 +0100] SSL alert: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.819254448 +0100] SSL alert: #011TLS_DHE_DSS_WITH_AES_256_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.820464679 +0100] SSL alert: #011TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.821632382 +0100] SSL alert: #011TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.822786869 +0100] SSL alert: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.823971028 +0100] SSL alert: #011TLS_DHE_DSS_WITH_AES_128_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.825053303 +0100] SSL alert: #011TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.826194181 +0100] SSL alert: #011TLS_RSA_WITH_AES_256_GCM_SHA384: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.827825315 +0100] SSL alert: #011TLS_RSA_WITH_AES_256_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.829462992 +0100] SSL alert: #011TLS_RSA_WITH_AES_256_CBC_SHA256: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.830793383 +0100] SSL alert: #011TLS_RSA_WITH_AES_128_GCM_SHA256: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.832242224 +0100] SSL alert: #011TLS_RSA_WITH_AES_128_CBC_SHA: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.833873583 +0100] SSL alert: #011TLS_RSA_WITH_AES_128_CBC_SHA256: enabled<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.885093482 +0100] SSL Initialization - Configured SSL version range: min: TLS1.0, max: TLS1.2<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.886826410 +0100] 389-Directory/<a href="http://1.3.5.10">1.3.5.10</a> B2016.309.1527 starting up<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.924968051 +0100] default_mr_indexer_create: warning - plugin [caseIgnoreIA5Match] does not handle caseExactIA5Match<br>Nov 17 15:05:07 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:07.960936427 +0100] WARNING: changelog: entry cache size 2097152 B is less than db size 15654912 B; We recommend to increase the entry cache size nsslapd-cachememsize.<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.051517901 +0100] schema-compat-plugin - scheduled schema-compat-plugin tree scan in about 5 seconds after the server startup!<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.088107275 +0100] NSACLPlugin - The ACL target cn=groups,cn=compat,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.089975405 +0100] NSACLPlugin - The ACL target cn=computers,cn=compat,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.091605059 +0100] NSACLPlugin - The ACL target cn=ng,cn=compat,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.093396173 +0100] NSACLPlugin - The ACL target ou=sudoers,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.095072910 +0100] NSACLPlugin - The ACL target cn=users,cn=compat,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.097647403 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.099159503 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.100703471 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.102286938 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.103852482 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.105586463 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.107026360 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.108476210 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.110187640 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.111655019 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.113841889 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.133500119 +0100] NSACLPlugin - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.135098802 +0100] NSACLPlugin - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=mydomain,dc=com does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.363531779 +0100] NSACLPlugin - The ACL target cn=automember rebuild membership,cn=tasks,cn=config does not exist<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.373037600 +0100] Skipping CoS Definition cn=Password Policy,cn=accounts,dc=ipa,dc=mydomain,dc=com--no CoS Templates found, which should be added before the CoS Definition.<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.412160395 +0100] set_krb5_creds - Could not get initial credentials for principal [ldap/<a href="mailto:mlv-ipa01.ipa.mydomain.com@IPA.MYDOMAIN.COM">mlv-ipa01.ipa.mydomain.com@IPA.MYDOMAIN.COM</a>] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested realm)<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.417620890 +0100] schema-compat-plugin - schema-compat-plugin tree scan will start in about 5 seconds!<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.430081973 +0100] slapd started. Listening on All Interfaces port 389 for LDAP requests<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.431273848 +0100] Listening on All Interfaces port 636 for LDAPS requests<br>Nov 17 15:05:08 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:08.432861124 +0100] Listening on /var/run/slapd-IPA-MYDOMAIN-COM.socket for LDAPI requests<br>Nov 17 15:05:08 mlv-ipa01 systemd[1]: Started 389 Directory Server IPA-MYDOMAIN-COM..<br>Nov 17 15:05:09 mlv-ipa01 systemd[1]: Starting Kerberos 5 KDC...<br>Nov 17 15:05:09 mlv-ipa01 systemd[1]: Started Kerberos 5 KDC.<br>Nov 17 15:05:09 mlv-ipa01 systemd[1]: Starting Kerberos 5 Password-changing and Administration...<br>Nov 17 15:05:09 mlv-ipa01 systemd[1]: Started Kerberos 5 Password-changing and Administration.<br>Nov 17 15:05:09 mlv-ipa01 systemd[1]: Starting Generate rndc key for BIND (DNS)...<br>Nov 17 15:05:09 mlv-ipa01 systemd[1]: Started Generate rndc key for BIND (DNS).<br>Nov 17 15:05:09 mlv-ipa01 systemd[1]: Starting Berkeley Internet Name Domain (DNS) with native PKCS#11...<br>Nov 17 15:05:09 mlv-ipa01 bash: zone localhost.localdomain/IN: loaded serial 0<br>Nov 17 15:05:09 mlv-ipa01 bash: zone localhost/IN: loaded serial 0<br>Nov 17 15:05:09 mlv-ipa01 bash: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0<br>Nov 17 15:05:09 mlv-ipa01 bash: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0<br>Nov 17 15:05:09 mlv-ipa01 bash: zone 0.in-addr.arpa/IN: loaded serial 0<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: starting BIND 9.9.4-RedHat-9.9.4-38.el7_3 -u named<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: built with '--build=x86_64-redhat-linux-gnu' '--host=x86_64-redhat-linux-gnu' '--program-prefix=' '--disable-dependency-tracking' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--datadir=/usr/share' '--includedir=/usr/include' '--libdir=/usr/lib64' '--libexecdir=/usr/libexec' '--sharedstatedir=/var/lib' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--with-libtool' '--localstatedir=/var' '--enable-threads' '--with-geoip' '--enable-ipv6' '--enable-filter-aaaa' '--enable-rrl' '--with-pic' '--disable-static' '--disable-openssl-version-check' '--enable-exportlib' '--with-export-libdir=/usr/lib64' '--with-export-includedir=/usr/include' '--includedir=/usr/include/bind9' '--enable-native-pkcs11' '--with-pkcs11=/usr/lib64/pkcs11/libsofthsm2.so' '--with-dlopen=yes' '--with-dlz-ldap=yes' '--with-dlz-postgres=yes' '--with-dlz-mysql=yes' '--with-dlz-filesystem=yes' '--with-dlz-bdb=yes' '--with-gssapi=yes' '--disable-isc-spnego' '--enable-fixed-rrset' '--with-docbook-xsl=/usr/share/sgml/docbook/xsl-stylesheets' 'build_alias=x86_64-redhat-linux-gnu' 'host_alias=x86_64-redhat-linux-gnu' 'CFLAGS= -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=generic' 'LDFLAGS=-Wl,-z,relro ' 'CPPFLAGS= -DDIG_SIGCHASE'<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: ----------------------------------------------------<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: BIND 9 is maintained by Internet Systems Consortium,<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: Inc. (ISC), a non-profit 501(c)(3) public-benefit<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: corporation. Support and training for BIND 9 are<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: available at <a href="https://www.isc.org/support">https://www.isc.org/support</a><br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: ----------------------------------------------------<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: adjusted limit on open files from 4096 to 1048576<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: found 8 CPUs, using 8 worker threads<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: using 8 UDP listeners per interface<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: using up to 4096 sockets<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: loading configuration from '/etc/named.conf'<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: reading built-in trusted keys from file '/etc/named.iscdlv.key'<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: initializing GeoIP Country (IPv4) (type 1) DB<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GEO-106FREE 20160607 Build 1 Copyright (c) 2016 MaxMind<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: initializing GeoIP Country (IPv6) (type 12) DB<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GEO-106FREE 20160607 Build 1 Copy<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP City (IPv4) (type 2) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP City (IPv4) (type 6) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP City (IPv6) (type 30) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP City (IPv6) (type 31) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP Region (type 3) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP Region (type 7) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP ISP (type 4) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP Org (type 5) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP AS (type 9) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP Domain (type 11) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: GeoIP NetSpeed (type 10) DB not available<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: using default UDP/IPv4 port range: [1024, 65535]<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: using default UDP/IPv6 port range: [1024, 65535]<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: listening on IPv6 interfaces, port 53<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: listening on IPv4 interface lo, 127.0.0.1#53<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: listening on IPv4 interface eth0, 192.168.0.65#53<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: generating session key for dynamic DNS<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: sizing zone task pool based on 6 zones<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: set up managed keys zone for view _default, file '/var/named/dynamic/managed-keys.bind'<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: bind-dyndb-ldap version 10.0 compiled at 16:25:21 Nov 4 2016, compiler 4.8.5 20150623 (Red Hat 4.8.5-11)<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: option 'serial_autoincrement' is not supported, ignoring<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: automatic empty zone: 10.IN-ADDR.ARPA<br>...<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: command channel listening on 127.0.0.1#953<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: command channel listening on ::1#953<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: managed-keys-zone: loaded serial 10165<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: ignoring inherited 'forward first;' for zone '.' - did you want 'forward only;' to override automatic empty zone '10.IN-ADDR.ARPA'?<br>...<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: zone <a href="http://ipa.mydomain.com/IN">ipa.mydomain.com/IN</a>: loaded serial 1479391509<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: zone <a href="http://ipa.mydomain.com/IN">ipa.mydomain.com/IN</a>: sending notifies (serial 1479391509)<br>Nov 17 15:05:09 mlv-ipa01 named-pkcs11[10634]: 1 master zones from LDAP instance 'ipa' loaded (1 zones defined, 0 inactive, 0 failed to load)<br>Nov 17 15:05:10 mlv-ipa01 ipa-httpd-kdcproxy: ipa : INFO KDC proxy enabled<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: httpd.service: main process exited, code=exited, status=1/FAILURE<br>Nov 17 15:05:11 mlv-ipa01 kill: kill: cannot find process ""<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: httpd.service: control process exited, code=exited status=1<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Failed to start The Apache HTTP Server.<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Unit httpd.service entered failed state.<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: httpd.service failed.<br>Nov 17 15:05:11 mlv-ipa01 systemctl[10657]: Job for httpd.service failed because the control process exited with error code. See "systemctl status httpd.service" and "journalctl -xe" for details.<br>Nov 17 15:05:11 mlv-ipa01 ipactl: Failed to start httpd Service<br>Nov 17 15:05:11 mlv-ipa01 ipactl: Shutting down<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Stopping Kerberos 5 KDC...<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Stopped Kerberos 5 KDC.<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Stopping Kerberos 5 Password-changing and Administration...<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: kadmin.service: main process exited, code=exited, status=2/INVALIDARGUMENT<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Stopped Kerberos 5 Password-changing and Administration.<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Unit kadmin.service entered failed state.<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: kadmin.service failed.<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Stopping Berkeley Internet Name Domain (DNS) with native PKCS#11...<br>Nov 17 15:05:11 mlv-ipa01 named-pkcs11[10634]: received control channel command 'stop'<br>Nov 17 15:05:11 mlv-ipa01 named-pkcs11[10634]: shutting down: flushing changes<br>Nov 17 15:05:11 mlv-ipa01 named-pkcs11[10634]: stopping command channel on 127.0.0.1#953<br>Nov 17 15:05:11 mlv-ipa01 named-pkcs11[10634]: stopping command channel on ::1#953<br>Nov 17 15:05:11 mlv-ipa01 named-pkcs11[10634]: zone <a href="http://ipa.mydomain.com/IN">ipa.mydomain.com/IN</a>: shutting down<br>Nov 17 15:05:11 mlv-ipa01 named-pkcs11[10634]: no longer listening on ::#53<br>Nov 17 15:05:11 mlv-ipa01 named-pkcs11[10634]: no longer listening on 127.0.0.1#53<br>Nov 17 15:05:11 mlv-ipa01 named-pkcs11[10634]: no longer listening on 192.168.0.65#53<br>Nov 17 15:05:11 mlv-ipa01 named-pkcs11[10634]: exiting<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Stopped Berkeley Internet Name Domain (DNS) with native PKCS#11.<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Stopping IPA memcached daemon, increases IPA server performance...<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Stopped IPA memcached daemon, increases IPA server performance.<br>Nov 17 15:05:11 mlv-ipa01 systemctl[10685]: Warning: httpd.service changed on disk. Run 'systemctl daemon-reload' to reload units.<br>Nov 17 15:05:11 mlv-ipa01 systemd[1]: Stopping 389 Directory Server IPA-MYDOMAIN-COM....<br>Nov 17 15:05:11 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:11.357603144 +0100] slapd shutting down - signaling operation threads - op stack size 1 max work q size 1 max work q stack size 1<br>Nov 17 15:05:11 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:11.359785218 +0100] slapd shutting down - waiting for 25 threads to terminate<br>Nov 17 15:05:11 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:11.361826680 +0100] slapd shutting down - closing down internal subsystems and plugins<br>Nov 17 15:05:13 mlv-ipa01 ns-slapd: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (No Kerberos credentials available (default cache: /tmp/krb5cc_996))<br>Nov 17 15:05:13 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:13.811837199 +0100] Waiting for 4 database threads to stop<br>Nov 17 15:05:14 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:14.000534924 +0100] All database threads now stopped<br>Nov 17 15:05:14 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:14.015405431 +0100] slapd shutting down - freed 1 work q stack objects - freed 1 op stack objects<br>Nov 17 15:05:14 mlv-ipa01 ns-slapd: [17/Nov/2016:15:05:14.437288197 +0100] slapd stopped.<br>Nov 17 15:05:14 mlv-ipa01 systemd[1]: Stopped 389 Directory Server IPA-MYDOMAIN-COM..<br>Nov 17 15:05:14 mlv-ipa01 ipactl: Hint: You can use --ignore-service-failure option for forced start in case that a non-critical service failed<br>Nov 17 15:05:14 mlv-ipa01 ipactl: Aborting ipactl<br>Nov 17 15:05:14 mlv-ipa01 ipactl: Starting Directory Service<br>Nov 17 15:05:14 mlv-ipa01 ipactl: Starting krb5kdc Service<br>Nov 17 15:05:14 mlv-ipa01 ipactl: Starting kadmin Service<br>Nov 17 15:05:14 mlv-ipa01 ipactl: Starting named Service<br>Nov 17 15:05:14 mlv-ipa01 ipactl: Starting ipa_memcached Service<br>Nov 17 15:05:14 mlv-ipa01 ipactl: Starting httpd Service<br>Nov 17 15:05:14 mlv-ipa01 systemd[1]: ipa.service: main process exited, code=exited, status=1/FAILURE<br>Nov 17 15:05:14 mlv-ipa01 systemd[1]: Failed to start Identity, Policy, Audit.<br>Nov 17 15:05:14 mlv-ipa01 systemd[1]: Unit ipa.service entered failed state.<br>Nov 17 15:05:14 mlv-ipa01 systemd[1]: ipa.service failed</i>.<br><br></div>Do you think there is a kerberos problem?<br><br></div>Please let me know, thanks.<br></div>Bye, Morgan<br><div><div><div><div><div><div><div><div><div><div><div class="gmail_extra"><br><div class="gmail_quote">2016-11-17 14:39 GMT+01:00 Florence Blanc-Renaud <span dir="ltr"><<a href="mailto:flo@redhat.com" target="_blank">flo@redhat.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-">On 11/17/2016 12:09 PM, Morgan Marodin wrote:<br>
</span><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-">
Hello.<br>
<br>
This morning I've tried to upgrade my IPA server, but the upgrade<br>
failed, and now the service doesn't start! :(<br>
<br>
If I try lo launch the upgrade manually this is the output:<br></span>
/[root@mlv-ipa01 download]# ipa-server-upgrade<div><div class="gmail-h5"><br>
Upgrading IPA:<br>
[1/8]: saving configuration<br>
[2/8]: disabling listeners<br>
[3/8]: enabling DS global lock<br>
[4/8]: starting directory server<br>
[5/8]: updating schema<br>
[6/8]: upgrading server<br>
[7/8]: stopping directory server<br>
[8/8]: restoring configuration<br>
Done.<br>
Update complete<br>
Upgrading IPA services<br>
Upgrading the configuration of the IPA services<br>
[Verifying that root certificate is published]<br>
[Migrate CRL publish directory]<br>
CRL tree already moved<br>
[Verifying that CA proxy configuration is correct]<br>
[Verifying that KDC configuration is using ipa-kdb backend]<br>
[Fix DS schema file syntax]<br>
Syntax already fixed<br>
[Removing RA cert from DS NSS database]<br>
RA cert already removed<br>
[Enable sidgen and extdom plugins by default]<br>
[Updating HTTPD service IPA configuration]<br>
[Updating mod_nss protocol versions]<br>
Protocol versions already updated<br>
[Updating mod_nss cipher suite]<br>
[Fixing trust flags in /etc/httpd/alias]<br>
Trust flags already processed<br>
[Exporting KRA agent PEM file]<br>
KRA is not enabled<br>
IPA server upgrade failed: Inspect /var/log/ipaupgrade.log and run<br>
command ipa-server-upgrade manually.<br>
Unexpected error - see /var/log/ipaupgrade.log for details:<br>
CalledProcessError: Command '/bin/systemctl start httpd.service'<br>
returned non-zero exit status 1<br>
The ipa-server-upgrade command failed. See /var/log/ipaupgrade.log for<br></div></div>
more information/<span class="gmail-"><br>
<br>
These are error logs of Apache:<br></span>
/[Thu Nov 17 11:48:45.498510 2016] [suexec:notice] [pid 5664] AH01232:<span class="gmail-"><br>
suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)<br>
[Thu Nov 17 11:48:45.499220 2016] [:warn] [pid 5664]<br>
NSSSessionCacheTimeout is deprecated. Ignoring.<br>
[Thu Nov 17 11:48:45.830910 2016] [:error] [pid 5664] Certificate not<br></span>
found: 'Server-Cert'/<br>
<br>
The problem seems to be the /Server-Cert /that could not be found.<br>
But if I try to execute the certutil command manually I can see it:/<span class="gmail-"><br>
[root@mlv-ipa01 log]# certutil -L -d /etc/httpd/alias/<br>
Certificate Nickname Trust<br>
Attributes<br>
<br>
SSL,S/MIME,JAR/XPI<br>
Signing-Cert u,u,u<br>
ipaCert u,u,u<br>
Server-Cert Pu,u,u<br>
</span><a href="http://IPA.MYDOMAIN.COM" rel="noreferrer" target="_blank">IPA.MYDOMAIN.COM</a> <<a href="http://IPA.MYDOMAIN.COM" rel="noreferrer" target="_blank">http://IPA.MYDOMAIN.COM</a>> IPA<br>
CA CT,C,C/<span class="gmail-"><br>
<br>
Could you help me?<br>
What could I try to do to restart my service?<br>
<br>
</span></blockquote>
Hi,<br>
<br>
I would first make sure that httpd is using /etc/httpd/alias as NSS DB (check the directive NSSCertificateDatabase in /etc/httpd/conf.d/nss.conf).<br>
Then it may be a file permission issue: the NSS DB should belong to root:apache (the relevant files are cert8.db, key3.db and secmod.db).<br>
You should also find a pwdfile.txt in the same directory, containing the NSS DB password. Check that the password is valid using<br>
certutil -K -d /etc/httpd/alias/ -f /etc/httpd/alias/pwdfile.txt<br>
(if the command succeeds then the password in pwdfile is OK).<br>
<br>
You can also enable mod-nss debug in /etc/httpd/conf/nss.conf by setting "LogLevel debug", and check the output in /var/log/httpd/error_log.<br>
<br>
HTH,<br>
Flo.<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
Thanks, Morgan<br>
<br>
<br><span class="gmail-HOEnZb"><font color="#888888">
</font></span></blockquote><span class="gmail-HOEnZb"><font color="#888888">
<br>
-- <br>
Manage your subscription for the Freeipa-users mailing list:<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" rel="noreferrer" target="_blank">https://www.redhat.com/mailman<wbr>/listinfo/freeipa-users</a><br>
Go to <a href="http://freeipa.org" rel="noreferrer" target="_blank">http://freeipa.org</a> for more info on the project<br>
</font></span></blockquote></div></div></div></div></div></div></div></div></div></div></div></div></div>