<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">2016-12-01 19:44 GMT+01:00 Rob Verduijn <span dir="ltr"><<a href="mailto:rob.verduijn@gmail.com" target="_blank">rob.verduijn@gmail.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">2016-12-01 17:20 GMT+01:00 Rob Crittenden <span dir="ltr"><<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-m_-3524027340237070699gmail-">Rob Verduijn wrote:<br>
><br>
><br>
> 2016-12-01 15:41 GMT+01:00 Rob Crittenden <<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a><br>
</span>> <mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>>>:<br>
<div><div class="gmail-m_-3524027340237070699gmail-h5">><br>
>     Rob Verduijn wrote:<br>
>     > Hello,<br>
>     ><br>
>     > For some reason my ipa server no longer boots.<br>
>     > It keeps trying to start pki-tomcat service.<br>
>     ><br>
>     > Does anybody know where I should start looking to get this fixed ?<br>
>     ><br>
>     > Rob Verduijn<br>
>     ><br>
>     > ipactl -d start gives this output:<br>
>     > ipa: DEBUG: The CA status is: check interrupted due to error: Command<br>
>     > ''/usr/bin/wget' '-S' '-O' '-' '--timeout=30' '--no-check-certificate'<br>
>     > '<a href="https://freeipa02.tjako.thuis:8443/ca/admin/ca/getStatus" rel="noreferrer" target="_blank">https://freeipa02.tjako.thuis<wbr>:8443/ca/admin/ca/getStatus</a><br>
>     <<a href="https://freeipa02.tjako.thuis:8443/ca/admin/ca/getStatus" rel="noreferrer" target="_blank">https://freeipa02.tjako.thui<wbr>s:8443/ca/admin/ca/getStatus</a>>'<wbr>' returned<br>
>     > non-zero exit status 8<br>
>     > ipa: DEBUG: Waiting for CA to start...<br>
>     > ipa: DEBUG: Starting external process<br>
>     > ipa: DEBUG: args='/usr/bin/wget' '-S' '-O' '-' '--timeout=30'<br>
>     > '--no-check-certificate'<br>
>     > '<a href="https://freeipa02.tjako.thuis:8443/ca/admin/ca/getStatus" rel="noreferrer" target="_blank">https://freeipa02.tjako.thuis<wbr>:8443/ca/admin/ca/getStatus</a><br>
>     <<a href="https://freeipa02.tjako.thuis:8443/ca/admin/ca/getStatus" rel="noreferrer" target="_blank">https://freeipa02.tjako.thui<wbr>s:8443/ca/admin/ca/getStatus</a>>'<br>
>     > ipa: DEBUG: Process finished, return code=8<br>
>     > ipa: DEBUG: stdout=<br>
>     > ipa: DEBUG: stderr=--2016-12-01 11:06:12--<br>
>     > <a href="https://freeipa02.tjako.thuis:8443/ca/admin/ca/getStatus" rel="noreferrer" target="_blank">https://freeipa02.tjako.thuis:<wbr>8443/ca/admin/ca/getStatus</a><br>
>     <<a href="https://freeipa02.tjako.thuis:8443/ca/admin/ca/getStatus" rel="noreferrer" target="_blank">https://freeipa02.tjako.thui<wbr>s:8443/ca/admin/ca/getStatus</a>><br>
>     > Resolving freeipa02.tjako.thuis (freeipa02.tjako.thuis)... 172.16.1.13<br>
>     > Connecting to freeipa02.tjako.thuis<br>
>     > (freeipa02.tjako.thuis)|172.16<wbr>.1.13|:8443... connected.<br>
>     > HTTP request sent, awaiting response...<br>
>     >   HTTP/1.1 500 Internal Server Error<br>
>     >   Server: Apache-Coyote/1.1<br>
>     >   Content-Type: text/html;charset=utf-8<br>
>     >   Content-Language: en<br>
>     >   Content-Length: 2134<br>
>     >   Date: Thu, 01 Dec 2016 10:06:13 GMT<br>
>     >   Connection: close<br>
>     > 2016-12-01 11:06:13 ERROR 500: Internal Server Error.<br>
>     ><br>
>     > There are also some java warnings in the logs, but its java and I can<br>
>     > never tell if its a serious error when java gives a warning.<br>
>     > Dec  1 09:53:59 freeipa02 server: Dec 01, 2016 9:53:59 AM<br>
>     > <a href="http://org.apache.catalina.startup.Se">org.apache.catalina.startup.Se</a><wbr>tAllPropertiesRule begin<br>
>     > Dec  1 09:53:59 freeipa02 server: WARNING:<br>
>     > [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property<br>
>     > 'serverCertNickFile' to<br>
>     > '/var/lib/pki/pki-tomcat/conf/<wbr>serverCertNick.conf' did not find a<br>
>     > matching property.<br>
>     > Dec  1 09:53:59 freeipa02 server: Dec 01, 2016 9:53:59 AM<br>
>     > <a href="http://org.apache.catalina.startup.Se">org.apache.catalina.startup.Se</a><wbr>tAllPropertiesRule begin<br>
>     > Dec  1 09:53:59 freeipa02 server: WARNING:<br>
>     > [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property<br>
>     > 'passwordFile' to '/var/lib/pki/pki-tomcat/conf/<wbr>password.conf' did not<br>
>     > find a matching property.<br>
>     > Dec  1 09:53:59 freeipa02 server: Dec 01, 2016 9:53:59 AM<br>
>     > <a href="http://org.apache.catalina.startup.Se">org.apache.catalina.startup.Se</a><wbr>tAllPropertiesRule begin<br>
>     > Dec  1 09:53:59 freeipa02 server: WARNING:<br>
>     > [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property<br>
>     > 'passwordClass' to '<a href="http://org.apache.tomcat.util.net" rel="noreferrer" target="_blank">org.apache.tomcat.util.net</a><br>
</div></div>>     <<a href="http://org.apache.tomcat.util.net" rel="noreferrer" target="_blank">http://org.apache.tomcat.uti<wbr>l.net</a>>.jss.PlainPasswordFile'<br>
<div><div class="gmail-m_-3524027340237070699gmail-h5">>     > did not find a matching property.<br>
>     > Dec  1 09:53:59 freeipa02 server: Dec 01, 2016 9:53:59 AM<br>
>     > <a href="http://org.apache.catalina.startup.Se">org.apache.catalina.startup.Se</a><wbr>tAllPropertiesRule begin<br>
>     > Dec  1 09:53:59 freeipa02 server: WARNING:<br>
>     > [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property<br>
>     > 'certdbDir' to '/var/lib/pki/pki-tomcat/alias<wbr>' did not find a matching<br>
>     > property.<br>
>     > Dec  1 09:53:59 freeipa02 server: Dec 01, 2016 9:53:59 AM<br>
>     > org.apache.tomcat.util.digeste<wbr>r.SetPropertiesRule begin<br>
>     > Dec  1 09:53:59 freeipa02 server: WARNING:<br>
>     > [SetPropertiesRule]{Server/Ser<wbr>vice/Engine/Host} Setting property<br>
>     > 'xmlValidation' to 'false' did not find a matching property.<br>
>     > Dec  1 09:53:59 freeipa02 server: Dec 01, 2016 9:53:59 AM<br>
>     > org.apache.tomcat.util.digeste<wbr>r.SetPropertiesRule begin<br>
>     > Dec  1 09:53:59 freeipa02 server: WARNING:<br>
>     > [SetPropertiesRule]{Server/Ser<wbr>vice/Engine/Host} Setting property<br>
>     > 'xmlNamespaceAware' to 'false' did not find a matching property.<br>
>     ><br>
>     ><br>
>     > I'm running centos7.2 x86_64 with the latest patches applied.<br>
>     > some package versions below<br>
>     > rpm -qa|egrep "ipa|tomcat"|sort<br>
>     > ipa-admintools-4.2.0-15.0.1.el<wbr>7.centos.19.x86_64<br>
>     > ipa-client-4.2.0-15.0.1.el7.ce<wbr>ntos.19.x86_64<br>
>     > ipa-python-4.2.0-15.0.1.el7.ce<wbr>ntos.19.x86_64<br>
>     > ipa-server-4.2.0-15.0.1.el7.ce<wbr>ntos.19.x86_64<br>
>     > ipa-server-dns-4.2.0-15.0.1.el<wbr>7.centos.19.x86_64<br>
>     > libipa_hbac-1.13.0-40.el7_2.12<wbr>.x86_64<br>
>     > python-iniparse-0.4-9.el7.noar<wbr>ch<br>
>     > python-libipa_hbac-1.13.0-40.e<wbr>l7_2.12.x86_64<br>
>     > sssd-ipa-1.13.0-40.el7_2.12.x8<wbr>6_64<br>
>     > tomcat-7.0.54-8.el7_2.noarch<br>
>     > tomcat-el-2.2-api-7.0.54-8.el7<wbr>_2.noarch<br>
>     > tomcat-jsp-2.2-api-7.0.54-8.el<wbr>7_2.noarch<br>
>     > tomcatjss-7.1.2-1.el7.noarch<br>
>     > tomcat-lib-7.0.54-8.el7_2.noar<wbr>ch<br>
>     > tomcat-servlet-3.0-api-7.0.54-<wbr>8.el7_2.noarch<br>
><br>
>     The debug log is quite verbose. I find it helpful to note where the<br>
>     previous log ended, starting and pulling the difference and going line<br>
>     by line. It sometimes fails in one place which cascades to others this<br>
>     generally makes it hard to grok.<br>
><br>
>     I'd also run `getcert list` and check to ensure that the CA subsystem<br>
>     certificates are still valid.<br>
><br>
>     rob<br>
><br>
><br>
><br>
> Hi,<br>
><br>
> My certs where indeed expired.<br>
> I did what was said in here<br>
> <a href="http://www.freeipa.org/page/Howto/CA_Certificate_Renewal" rel="noreferrer" target="_blank">http://www.freeipa.org/page/Ho<wbr>wto/CA_Certificate_Renewal</a><br>
> And now they are all valid again.<br>
><br>
> However it is still stuck at the same spot.<br>
> It keeps waiting for the ca to start and gets an internal error.<br>
><br>
> In the pki-cataline logs this keeps repeating :<br>
> Dec 01, 2016 4:22:44 PM org.apache.catalina.core.Conta<wbr>inerBase<br>
> backgroundProcess<br>
> WARNING: Exception processing realm<br>
> com.netscape.cms.tomcat.ProxyR<wbr>ealm@6934e456 background process<br>
> java.lang.NullPointerException<br>
>         at<br>
> com.netscape.cms.tomcat.ProxyR<wbr>ealm.backgroundProcess(ProxyRe<wbr>alm.java:108)<br>
>         at<br>
> org.apache.catalina.core.Conta<wbr>inerBase.backgroundProcess(Con<wbr>tainerBase.java:1360)<br>
>         at<br>
> org.apache.catalina.core.Conta<wbr>inerBase$ContainerBackgroundPr<wbr>ocessor.processChildren(<wbr>ContainerBase.java:1530)<br>
>         at<br>
> org.apache.catalina.core.Conta<wbr>inerBase$ContainerBackgroundPr<wbr>ocessor.processChildren(<wbr>ContainerBase.java:1540)<br>
>         at<br>
> org.apache.catalina.core.Conta<wbr>inerBase$ContainerBackgroundPr<wbr>ocessor.processChildren(<wbr>ContainerBase.java:1540)<br>
>         at<br>
> org.apache.catalina.core.Conta<wbr>inerBase$ContainerBackgroundPr<wbr>ocessor.run(ContainerBase.<wbr>java:1519)<br>
>         at java.lang.Thread.run(Thread.ja<wbr>va:745)<br>
><br>
> I keep digging through the logs, but they are rather overwhelming.<br>
><br>
> Have you got any pointers for me ?<br>
<br>
</div></div>My only recommendation is to read top-down instead of bottom up as one<br>
would normally do. Look for the selftest and see if it was successful.<br>
If it wasn't then nothing will work.<br>
<span class="gmail-m_-3524027340237070699gmail-HOEnZb"><font color="#888888"><br>
rob<br>
</font></span></blockquote></div><br><br><br></div><div class="gmail_extra">in the pki-catalina log I find a lot of warnings are these real warnings or just noise from tomcat ?<br>Dec 01, 2016 6:18:40 PM org.apache.catalina.startup.<wbr>SetAllPropertiesRule begin<br>WARNING: [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property 'enableOCSP' to 'false' did not find a matching property.<br>Dec 01, 2016 6:18:40 PM org.apache.catalina.startup.<wbr>SetAllPropertiesRule begin<br>WARNING: [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property 'ocspResponderURL' to '<a href="http://freeipa02.tjako.thuis:9080/ca/ocsp" target="_blank">http://freeipa02.tjako.thuis:<wbr>9080/ca/ocsp</a>' did not find a matching property.<br>Dec 01, 2016 6:18:40 PM org.apache.catalina.startup.<wbr>SetAllPropertiesRule begin<br>WARNING: [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property 'ocspResponderCertNickname' to 'ocspSigningCert cert-pki-ca' did not find a matching property.<br>Dec 01, 2016 6:18:40 PM org.apache.catalina.startup.<wbr>SetAllPropertiesRule begin<br>WARNING: [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property 'ocspCacheSize' to '1000' did not find a matching property.<br>Dec 01, 2016 6:18:40 PM org.apache.catalina.startup.<wbr>SetAllPropertiesRule begin<br>WARNING: [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property 'ocspMinCacheEntryDuration' to '60' did not find a matching property.<br>Dec 01, 2016 6:18:40 PM org.apache.catalina.startup.<wbr>SetAllPropertiesRule begin<br>WARNING: [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property 'ocspMaxCacheEntryDuration' to '120' did not find a matching property.<br>Dec 01, 2016 6:18:40 PM org.apache.catalina.startup.<wbr>SetAllPropertiesRule begin<br>WARNING: [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property 'ocspTimeout' to '10' did not find a matching property.<br>Dec 01, 2016 6:18:40 PM org.apache.catalina.startup.<wbr>SetAllPropertiesRule begin<br>WARNING: [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property 'strictCiphers' to 'true' did not find a matching property.<br>Dec 01, 2016 6:18:40 PM org.apache.catalina.startup.<wbr>SetAllPropertiesRule begin<br>WARNING: [SetAllPropertiesRule]{Server/<wbr>Service/Connector} Setting property 'sslOptions' to 'ssl2=false,ssl3=false,tls=<wbr>true' did not find a matching property.<span class="gmail-HOEnZb"><font color="#888888"><br></font></span></div><span class="gmail-HOEnZb"><font color="#888888"><div class="gmail_extra"><br>Rob Verduijn<br></div></font></span></div>
<br>--<br>
Manage your subscription for the Freeipa-users mailing list:<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" rel="noreferrer" target="_blank">https://www.redhat.com/<wbr>mailman/listinfo/freeipa-users</a><br>
Go to <a href="http://freeipa.org" rel="noreferrer" target="_blank">http://freeipa.org</a> for more info on the project<br></blockquote></div><br></div><div class="gmail_extra">Hi again,<br><br></div><div class="gmail_extra">After some serious digging, I found something in the catalina log which happens at the same time in the slapd errors log<br><br>==> /var/log/pki/pki-tomcat/catalina.2016-11-23.log <==<br>INFO: Deploying configuration descriptor /etc/pki/pki-tomcat/Catalina/localhost/ca.xml<br><br>==> /var/log/dirsrv/slapd-TJAKO-THUIS/errors <==<br>[23/Nov/2016:14:38:19 +0100] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 107 (Transport endpoint is not connected)<br>[23/Nov/2016:14:38:19 +0100] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)<br>[23/Nov/2016:14:38:19 +0100] slapi_ldap_bind - Error: could not send startTLS request: error -1 (Can't contact LDAP server) errno 107 (Transport endpoint is not connected)<br><br></div><div class="gmail_extra">Those are the first errors after which many follow.<br><br></div><div class="gmail_extra">Manual binding to the ldap works ofcourse.<br></div><div class="gmail_extra">What could be causing this ?<br><br></div><div class="gmail_extra">Rob verduijn<br></div><div class="gmail_extra"><br></div></div>