Oliver Nixon via FreeIPA-users wrote:
Hi,
I'm encountering the same issue after upgrading to 4.9.12. I had previously imported users from another FreeIPA deployment and their UIDs were outside of the defined ID ranges. I've created a new ID range to encompass these and run the following but the SIDs still don't get generated: ]# /usr/libexec/ipa/oddjob/org.freeipa.server.config-enable-sid --netbios-name DOMAIN-NAME --add-sids Configuring SID generation [1/8]: creating samba domain object Samba domain object already exists [2/8]: adding admin(group) SIDs Admin SID already set, nothing to do Admin group SID already set, nothing to do [3/8]: adding RID bases RID bases already set, nothing to do [4/8]: updating Kerberos config 'dns_lookup_kdc' already set to 'true', nothing to do. [5/8]: activating sidgen task Sidgen task plugin already configured, nothing to do [6/8]: restarting Directory Server to take MS PAC and LDAP plugins changes into account [7/8]: adding fallback group Fallback group already set, nothing to do [8/8]: adding SIDs to existing users and groups This step may take considerable amount of time, please wait.. Done.
You need to look in /var/log/dirsrv/slapd-REALM/errors for the reason for failure.
rob