Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support DAL version 5 and version 6 #205

Closed
wants to merge 1 commit into from

Conversation

simo5
Copy link
Contributor

@simo5 simo5 commented Nov 1, 2016

Should fix bz#1389866
(untested)

@frozencemetery
Copy link
Contributor

Thank you for fixing this, and futureproofing the next version bump. Unless freeipa has a policy against it, I would prefer the use of designated initializers here for additional protection against breakage in the future, as you mention in the past this has occasionally been changed by accident without bumping the number.

@simo5
Copy link
Contributor Author

simo5 commented Nov 2, 2016

Updated

Copy link
Contributor

@frozencemetery frozencemetery left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, thanks!

@tkrizek tkrizek self-assigned this Nov 7, 2016
@tkrizek
Copy link
Contributor

tkrizek commented Nov 7, 2016

NACK

ipa-server-install will fail at:

Configuring kadmin
  [1/2]: starting kadmin 
  [2/2]: configuring kadmin to start on boot
Done configuring kadmin.
ipa.ipapython.install.cli.install_tool(Server): ERROR    CA did not start in 300.0s
ipa.ipapython.install.cli.install_tool(Server): ERROR    The ipa-server-install command failed

From /var/log/pki/pki-tomcat/ca/debug, it seems PKI can't authenticate towards LDAP:

[07/Nov/2016:16:42:11][localhost-startStop-1]: SSL handshake happened
Could not connect to LDAP server host vm-059.abc.idm.lab.eng.brq.redhat.com port 636 Error netscape.ldap.LDAPException: Authentication failed (48)

@simo5
Copy link
Contributor Author

simo5 commented Nov 7, 2016

On Mon, 2016-11-07 at 08:11 -0800, Tomas Krizek wrote:

NACK

ipa-server-install will fail at:

Configuring kadmin
  [1/2]: starting kadmin 
  [2/2]: configuring kadmin to start on boot
Done configuring kadmin.
ipa.ipapython.install.cli.install_tool(Server): ERROR    CA did not start in 300.0s
ipa.ipapython.install.cli.install_tool(Server): ERROR    The ipa-server-install command failed

From /var/log/pki/pki-tomcat/ca/debug, it seems PKI can't authenticate towards LDAP:

[07/Nov/2016:16:42:11][localhost-startStop-1]: SSL handshake happened
Could not connect to LDAP server host vm-059.abc.idm.lab.eng.brq.redhat.com port 636 Error netscape.ldap.LDAPException: Authentication failed (48)

I've seen this error recently too, but it is unrelated, re-installed on
F25 and it went away.
I think there is some issue with dogtag in some conditions when you
re-install, although I could not figure what it is.

Simo.

Simo Sorce * Red Hat, Inc * New York

@tkrizek
Copy link
Contributor

tkrizek commented Nov 7, 2016

It is not caused by re-installing. I've created a new VM when I was testing it.

@simo5
Copy link
Contributor Author

simo5 commented Nov 7, 2016

Sure, but I do not see how a change in the KDC DAL, can affect PKI connecting to LDAP.
Does this problem go away if you remove the patch and re-build/install on the same machine ?

@tkrizek
Copy link
Contributor

tkrizek commented Nov 7, 2016

The issue above is indeed unrelated to this patch. Since KDC installation passed, I think it's safe to assume the patch works.

@simo5 simo5 added the ack Pull Request approved, can be merged label Nov 7, 2016
@simo5
Copy link
Contributor Author

simo5 commented Nov 7, 2016

I just verified I reproduce your error in my tree without the patch.

@MartinBasti
Copy link
Contributor

https://fedorahosted.org/freeipa/ticket/6466

Commit should have upstream ticket inside

@simo5
Copy link
Contributor Author

simo5 commented Nov 8, 2016

There was no upstream ticket when I created the commit :-)
I'll add.

@MartinBasti MartinBasti added the pushed Pull Request has already been pushed label Nov 10, 2016
@MartinBasti
Copy link
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ack Pull Request approved, can be merged pushed Pull Request has already been pushed
Projects
None yet
4 participants