I'm unable to promote replica using admin credentials.
ipa-replica-install fails with following error:
ipa.ipapython.install.cli.install_tool(Replica): ERROR Insufficient access: Insufficient 'add' privilege to add the entry 'krbprincipalname=ldap/vm-046.abc.idm.lab.eng.brq.redhat.com@DOM-058-082.ABC.IDM.LAB.ENG.BRQ.REDHAT.COM,cn=services,cn=accounts,dc=dom-058-082,dc=abc,dc=idm,dc=lab,dc=eng,dc=brq,dc=redhat,dc=com'.
389-ds-base-1.3.5.6-1.fc24.x86_64 IPA: eec440b
I'm going to attach full server install log.
attachment ipareplica-install.log.bz2
I can reproduce a failure but a different one. Would you described what differs from my tests:
On master side: freeipa-server-4.4.0.201606231659GITeec440b-0.fc24.x86_64 389-ds-base-1.3.5.6-1.fc24.x86_64 ipa-server-install --hostname=<master-vm-fqdn> -p Secret123 -a Secret123 --domain <domain> -U --realm <REALM> on replica side: freeipa-server-4.4.0.201606231711GITeec440b-0.fc24.x86_64 389-ds-base-1.3.5.6-1.fc24.x86_64 ipa-client-install --domain <domain> --realm <REALM> --server <<master-vm-fqdn> -p admin -w Secret123 -U ipa-replica-install ==> ipa.ipaserver.plugins.ldap2.ldap2: ERROR Configured time limit exceeded while getting entries (base DN: cn=ipaservers,cn=hostgroups,cn=accounts,<suffix>, filter: None)
Interesting. It could be a deadlock in DS or just a slow VM. Is the time limit reproducible repeatedly?
For information, I was able to reproduce the 'Insufficient access...' issue.
I was no longer able to reproduce with the patch 00165 fixed
a6dffbf IPA API: Do not force setting krbCanonicalName on newly created entries fd840a9 mod_auth_gssapi: enable unique credential caches names 1ce8d32 ipapwd_extop should use TARGET_DN defined by a pre-extop plugin d64513f Tests: Fix ipatests/test_ipaserver/test_rpcserver.py 13328bc topo segment-add: validate that both masters support target suffix ...
master:
Regresion caused by kerberos aliases commits
Metadata Update from @pspacek: - Issue assigned to mbabinsk - Issue set to the milestone: FreeIPA 4.4
Login to comment on this ticket.