On 12/11/18 11:23 AM, 74cmonty via FreeIPA-users wrote:
Hello Flo,
I successfully installed FreeIPA 4.7.2 packages on replica server:
```
[root@ipa-replica ~]# rpm -q freeipa-server freeipa-client ipa-server ipa-client 3
89-ds-base
pki-ca krb5-server
freeipa-server-4.7.2-1.fc29.x86_64
freeipa-client-4.7.2-1.fc29.x86_64
Das Paket ipa-server ist nicht installiert
Das Paket ipa-client ist nicht installiert
389-ds-base-1.4.0.16-1.fc29.x86_64
pki-ca-10.6.8-3.fc29.noarch
```
However, the upgrade is failing.
When I execute this command `ipa-server-upgrade` manually I get this error:
```
ipaserver.install.service: DEBUG: [5/9]: starting directory server
[5/9]: starting directory server
ipapython.ipautil: DEBUG: Starting external process
ipapython.ipautil: DEBUG: args=['/bin/systemctl', 'start',
'dirsrv@BISZUMBITTERENE
N-DE.service']
ipapython.ipautil: DEBUG: Process finished, return code=1
ipapython.ipautil: DEBUG: stdout=
ipapython.ipautil: DEBUG: stderr=Job for dirsrv(a)BISZUMBITTERENEN-DE.service failed
because the
control process exited with error code.
See "systemctl status dirsrv(a)BISZUMBITTERENEN-DE.service" and "journalctl
-xe" for
details.
```
So I checked log `/var/log/dirsrv/slapd-BISZUMBITTERENEN-DE/errors` and found this:
```
[root@ipa-replica ~]# tail -n 40 /var/log/dirsrv/slapd-BISZUMBITTERENEN-DE/errors
[11/Dec/2018:10:45:10.505923459 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=computers,cn=compat,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.515595444 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=ng,cn=compat,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.524433521 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
ou=sudoers,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.534653076 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=users,cn=compat,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.543444060 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.550404494 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.559231814 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.574312715 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.581500986 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.588207817 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.598901345 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.608874140 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.624449543 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.635198157 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.644514201 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=vaults,cn=kra,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.652438328 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=ad,cn=etc,dc=biszumbitterenen,dc=de does not exist
[11/Dec/2018:10:45:10.666047779 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=biszumbitterenen,dc=de does
not exist
[11/Dec/2018:10:45:10.676464447 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=biszumbitterenen,dc=de does
not exist
[11/Dec/2018:10:45:10.758108000 +0100] - ERR - NSACLPlugin - acl_parse - The ACL target
cn=automember rebuild membership,cn=tasks,cn=config does not exist
[11/Dec/2018:10:45:10.768519636 +0100] - ERR - cos-plugin - cos_dn_defs_cb - Skipping CoS
Definition cn=Password Policy,cn=accounts,dc=biszumbitterenen,dc=de--no CoS Templates
found, which should be added before the CoS Definition.
[11/Dec/2018:10:45:10.807844822 +0100] - ERR - set_krb5_creds - Could not get initial
credentials for principal [ldap/ipa-replica.biszumbitterenen.de(a)BISZUMBITTERENEN.DE] in
keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328228 (Cannot contact any KDC for requested
realm)
[11/Dec/2018:10:45:10.822417907 +0100] - INFO - slapd_daemon - slapd started. Listening
on /var/run/slapd-BISZUMBITTERENEN-DE.socket for LDAPI requests
[11/Dec/2018:10:45:10.991091930 +0100] - INFO - op_thread_cleanup - slapd shutting down -
signaling operation threads - op stack size 3 max work q size 2 max work q stack size 2
[11/Dec/2018:10:45:11.001531238 +0100] - INFO - slapd_daemon - slapd shutting down -
waiting for 2 threads to terminate
[11/Dec/2018:10:45:11.014214280 +0100] - INFO - slapd_daemon - slapd shutting down -
closing down internal subsystems and plugins
[11/Dec/2018:10:47:10.908408935 +0100] - ERR - NSMMReplicationPlugin - bind_and_check_pwp
- agmt="cn=meToipa-master.biszumbitterenen.de" (ipa-master:389) - Replication
bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) ()
[11/Dec/2018:10:47:11.147205700 +0100] - INFO - dblayer_pre_close - Waiting for 4
database threads to stop
[11/Dec/2018:10:47:13.151397617 +0100] - INFO - dblayer_pre_close - All database threads
now stopped
[11/Dec/2018:10:47:13.174133191 +0100] - INFO - ldbm_back_instance_set_destructor - Set
of instances destroyed
[11/Dec/2018:10:47:13.182242796 +0100] - INFO - connection_post_shutdown_cleanup - slapd
shutting down - freed 2 work q stack objects - freed 3 op stack objects
[11/Dec/2018:10:47:13.193043173 +0100] - INFO - main - slapd stopped.
[11/Dec/2018:10:49:34.420307507 +0100] - ERR - init_schema_dse_ext - Could not add
attribute type "objectClass" to the schema: attribute type objectClass: Unknown
attribute syntax OID "1.3.6.1.4.1.1466.115.121.1.15"
[11/Dec/2018:10:49:34.436344560 +0100] - ERR - dse_read_one_file - The entry cn=schema in
file /usr/share/dirsrv/schema/00core.ldif (lineno: 1) is invalid, error code 21 (Invalid
syntax) - attribute type aci: Unknown attribute syntax OID
"1.3.6.1.4.1.1466.115.121.1.15"
[11/Dec/2018:10:49:34.443437573 +0100] - ERR - setup_internal_backends - Please edit the
file to correct the reported problems and then restart the server.
[11/Dec/2018:10:50:08.568553528 +0100] - ERR - init_schema_dse_ext - Could not add
attribute type "objectClass" to the schema: attribute type objectClass: Unknown
attribute syntax OID "1.3.6.1.4.1.1466.115.121.1.15"
[11/Dec/2018:10:50:08.580692294 +0100] - ERR - dse_read_one_file - The entry cn=schema in
file /usr/share/dirsrv/schema/00core.ldif (lineno: 1) is invalid, error code 21 (Invalid
syntax) - attribute type aci: Unknown attribute syntax OID
"1.3.6.1.4.1.1466.115.121.1.15"
[11/Dec/2018:10:50:08.588399834 +0100] - ERR - setup_internal_backends - Please edit the
file to correct the reported problems and then restart the server.
[11/Dec/2018:10:52:26.598725479 +0100] - ERR - init_schema_dse_ext - Could not add
attribute type "objectClass" to the schema: attribute type objectClass: Unknown
attribute syntax OID "1.3.6.1.4.1.1466.115.121.1.15"
[11/Dec/2018:10:52:26.610499920 +0100] - ERR - dse_read_one_file - The entry cn=schema in
file /usr/share/dirsrv/schema/00core.ldif (lineno: 1) is invalid, error code 21 (Invalid
syntax) - attribute type aci: Unknown attribute syntax OID
"1.3.6.1.4.1.1466.115.121.1.15"
[11/Dec/2018:10:52:26.618930090 +0100] - ERR - setup_internal_backends - Please edit the
file to correct the reported problems and then restart the server.
```
And this is the relevant content of file `/usr/share/dirsrv/schema/00core.ldif`:
```
attributeTypes: ( 2.16.840.1.113730.3.1.55 NAME 'aci'
DESC 'Netscape defined access control information attribute type'
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15
USAGE directoryOperation
X-ORIGIN 'Netscape Directory Server' )
```
Comparing this content with `/usr/share/dirsrv/schema/00core.ldif` on master server
there's no difference.
I thought to restart deployment of replica server from scratch, but I cannot delete the
host ipa-replica in WebUI.Hi,
what is the error you are seeing?
If the replica is not a single point of failure for any service (CA,
DNS, replication to other master...) you can do the following:
(on replica) ipa-server-install --uninstall -U
(on master) ipa-replica-manage del <replica> --force --cleanup
then retry the replica installation.
flo
Any advise?
_______________________________________________
FreeIPA-users mailing list -- freeipa-users(a)lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-leave(a)lists.fedorahosted.org
Fedora Code of Conduct:
https://getfedora.org/code-of-conduct.html
List Guidelines:
https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedoraho...