Jamal Mahmoud / Pipeline TD 35 Fitzwilliam Street Upper, Dublin. | |
Jamal Mahmoud wrote:
> Sure thing,
> Output on* lithium*:
>
> [root@lithium ~]# ipa-replica-manage del oxygen.eggvfx.ie
> <http://oxygen.eggvfx.ie> --force --cleanup
> oxygen.eggvfx.ie <http://oxygen.eggvfx.ie>: server not found
What is baffling me the most is that the string 'server not found' is
not to be found in the IPA source. I can't tell where that is being
generated.
Can you provide a snippet of the 389-ds access log when you request the
deletion? That is in /var/log/dirsrv/slapd-REALM/access
Note that the log is write buffered so the content may not appear
immediately.
Seeing the queries being made and what the responses/errors are might
give me some ideas.
rob
>
>
> [root@lithium ~]# ipa domainlevel-get
> -----------------------
> Current domain level: 1
> -----------------------
>
>
> Output on *nitrogen*:
>
> [root@nitrogen ~]# ipa-replica-manage del oxygen.eggvfx.ie
> <http://oxygen.eggvfx.ie> --force --cleanup
> oxygen.eggvfx.ie <http://oxygen.eggvfx.ie>: server not found
>
>
> [root@nitrogen ~]# ipa domainlevel-get
> -----------------------
> Current domain level: 1
> -----------------------
>
> I hope this helps,
>
> Jamal
>
> <http://www.egg.ie/>
>
>
>
> *Jamal Mahmoud* / Pipeline TD
> jamal.mahmoud@egg.ie <mailto:jamal.mahmoud@egg.ie>
>
> 35 Fitzwilliam Street Upper, Dublin.
> P: +353 1 6345440
>
> Twitter <https://twitter.com/EggPost>
> <https://www.facebook.com/egg.post/ > LinkedIn
> <http://www.linkedin.com/in/jamalmahmoud > Vimeo
> <https://vimeo.com/user9887735>
>
>
> <mailto:rcritten@redhat.com>> wrote:
>
> Jamal Mahmoud via FreeIPA-users wrote:
> > Hi Rob,
> >
> > Just wondering if you had time to look at this issue for me? Still stuck
> > in a state of limbo with this IDM and i have run out of options. Any
> > help in resolving this issue would be appreciated.
>
> A few more questions.
>
> What is the output of: ipa domainlevel-get
>
> Can you show the full output of ipa-replica-manage del oxygen... --force
> --cleanup
>
> And on what master are you running that?
>
> rob
>
> >
> > Many Thanks,
> > Jamal
> >
> >
> > On 1 February 2018 at 17:04, Jamal Mahmoud <jamal.mahmoud@egg.ie <mailto:jamal.mahmoud@egg.ie>
> <mailto:jamal.mahmoud@egg.ie <mailto:jamal.mahmoud@egg.ie>>> > <mailto:jamal.mahmoud@egg.ie <mailto:jamal.mahmoud@egg.ie>>> wrote:
> >
> > Sorry about the lack of clarification Rob!
> >
> > I have 3 servers, all running CentOS 7.4, FreeIPA version 4.5.0. the
> > hostnames are lithium, nitrogen and the recently deceased oxygen.
> > all are masters under the same Realm which is EGGVFX.IE <http://EGGVFX.IE>
> > <http://EGGVFX.IE>
> >
> > The "server not found" error is exactly what shows when i try to
> > delete the server from command line or the Web UI.
> >
> > When i run ipa-replica-manage list -v `hostname` this is the output
> > from the servers:
> >
> > Lithium Output:
> > root@lithium# ipa-replica-manage list -v `hostname`
> > nitrogen.eggvfx.ie <http://nitrogen.eggvfx.ie>
> <http://nitrogen.eggvfx.ie>: replica
> > last init status: 0 Total update succeeded
> > last init ended: 2018-02-01 10:51:14+00:00
> > last update status: Error (0) Replica acquired successfully:
> > Incremental update succeeded
> > last update ended: 2018-02-01 16:24:37+00:00
> >
> > Nitrogen Output:
> > root@nitrogen# ipa-replica-manage list -v `hostname`
> > lithium.eggvfx.ie <http://lithium.eggvfx.ie>
> <http://lithium.eggvfx.ie>: replica
> > last init status: None
> > last init ended: 1970-01-01 00:00:00+00:00
> > last update status: Error (0) Replica acquired successfully:
> > Incremental update succeeded
> > last update ended: 2018-02-01 10:48:18+00:00
> > oxygen.eggvfx.ie <http://oxygen.eggvfx.ie>
> <http://oxygen.eggvfx.ie>: replica
> > last init status: None
> > last init ended: 1970-01-01 00:00:00+00:00
> > last update status: Error (-1) Problem connecting to replica -
> > LDAP error: Can't contact LDAP server (connection error)
> > last update ended: 1970-01-01 00:00:00+00:00
> >
> > There is no entries for oxygen in host-find. I hope this helps clear
> > the story a bit for you.
> >
> > <http://www.egg.ie/>
> >
> >
> >
> > *Jamal Mahmoud* / Pipeline TD
> > jamal.mahmoud@egg.ie <mailto:jamal.mahmoud@egg.ie>
> >
> > 35 Fitzwilliam Street Upper, Dublin.
> > P: +353 1 6345440 <tel:%2B353%201%206345440>
> <tel:+353%201%20634%205440>
> >
> > Twitter <https://twitter.com/EggPost>
> > <https://www.facebook.com/egg.post/
> <https://www.facebook.com/egg.post/ >> LinkedIn
> > <http://www.linkedin.com/in/jamalmahmoud
> <http://www.linkedin.com/in/jamalmahmoud >> Vimeo
> > <https://vimeo.com/user9887735 >
> >
> >
> > On 1 February 2018 at 15:30, Rob Crittenden <rcritten@redhat.com <mailto:rcritten@redhat.com>
> > <mailto:freeipa-users@lists.> > <mailto:rcritten@redhat.com <mailto:rcritten@redhat.com>>> wrote:
> >
> > Jamal Mahmoud via FreeIPA-users wrote:
> > > I'm having strange issues with removing one of my
> freeIPA masters, I
> > > managed to mess up the deletion process and my system
> seems to be stuck
> > > in a state of limbo, my current setup is 3 servers ( 1
> has been
> > > decommissioned) that all share the CA/Domain
> responsibilities. When i
> > > run the command .>
> > > *ipa-replica-manage list*
> > > *
> > > *it produces 3 servers as active masters, when this is not
> > true as i
> > > have uninstalled ipa-server on one. Trying to delete it
> through that
> > > command has given me no luck, even using *--force* and
> > *--cleanup* does
> > > not work. the same error output appears:
> > >
> > > *oxygen.eggvfx.ie <http://oxygen.eggvfx.ie>
> <http://oxygen.eggvfx.ie>
> > <http://oxygen.eggvfx.ie>: server not found*
> >
> > I think we need more information. What version of IPA is
> this, what
> > distribution?
> >
> > Is the above error the exact error you are getting?
> >
> > As I understand it you ran ipa-server-install --uninstall and
> > THEN tried
> > to delete the master?
> >
> > What does ipa-replica-manage list -v `hostname` show on one of
> > the other
> > masters?
> >
> > > *
> > > *
> > > I'm not very good with ldap tools but after running
> > >
> > > *ldapsearch -x *
> > > *
> > > *there is a reference to the oxygen server still sitting in
> > there, it
> > > seems that the dirty entry is still hanging around my
> system, i'm
> > > wondering if there is any way to resolve this?
> > >
> > > ldapsearch output:
> > > *defaultServerList: oxygen.eggvfx.ie
> <http://oxygen.eggvfx.ie> <http://oxygen.eggvfx.ie>
> > <http://oxygen.eggvfx.ie>
> > > nitrogen.eggvfx.ie <http://nitrogen.eggvfx.ie>
> <http://nitrogen.eggvfx.ie>
> > <http://nitrogen.eggvfx.ie> lithium.eggvfx.ie
> <http://lithium.eggvfx.ie>
> > <http://lithium.eggvfx.ie>
> > > <http://lithium.eggvfx.ie>*
> >
> > An anonymous LDAP search won't show much.
> >
> > Does it show up in host-find?
> >
> > rob
> >
> > > *
> > > Looking at the topology graph in the web ui i can see
> that there are
> > > still ties between one of my servers and oxygen. It will
> also not allow
> > > me to delete the server ties ( error: *Server is
> unwilling to
> > perform:
> > > Removal of Segment disconnects topology.Deletion not
> > allowed.)* nor will
> > > the ui allow me to delete the IPA server
> (*oxygen.eggvfx.ie <http://oxygen.eggvfx.ie>
> > <http://oxygen.eggvfx.ie>
> > > <http://oxygen.eggvfx.ie>: server not found*)
> > >
> > > Any help is greatly appreciated,
> > >
> > > Many Thanks,
> > > Jamal Mahmoud
> > >
> > >
> > >
> > > _______________________________________________
> > > FreeIPA-users mailing list --
> > freeipa-users@lists.fedorahosted.org
> <mailto:freeipa-users@lists.fedorahosted.org >
fedorahosted.org
> <mailto:freeipa-users@lists.fedorahosted.org >>
> > > To unsubscribe send an email to
> > freeipa-users-leave@lists.fedorahosted.org
> <mailto:freeipa-users-leave@lists.fedorahosted.org >
> > <mailto:freeipa-users-leave@lists.fedorahosted.org
> <mailto:freeipa-users-leave@lists.fedorahosted.org >>
> > >
> >
> >
> >
> >
> >
> > _______________________________________________
> > FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
> <mailto:freeipa-users@lists.fedorahosted.org >
> > To unsubscribe send an email to
> freeipa-users-leave@lists.fedorahosted.org
> <mailto:freeipa-users-leave@lists.fedorahosted.org >
> >
>
>