#7126 FreeIPA/IdM installations which were upgraded from versions with 389 DS prior to 1.3.3.0 doesn't have whomai plugin enabled and thus startup of Web UI fails
Closed: fixed 2 years ago Opened 2 years ago by pvomacka.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1484826

Description of problem:
FreeIPA/IdM installations which were created with directory server preceding DS
1.3.3.0 doesn't have DS whoami plugin enabled.

Whoami plugin is required for whoami IPA API call which is part of Web UI
startup. Whoami command is executed after login to get who is the user. With
missing plugin entablement this command fails with protocol error and thus
loading of Web UI fails.

In httpd error log the error is:

ipa: ERROR: non-public: PROTOCOL_ERROR: {'info': 'unsupported extended
operation', 'desc': 'Protocol error'}

Workaround:
Enable the plugin by modifying dse.ldif when DS is shutdown. Or by executing
LDAP mod operation as Directory Manager with following ldif:

# whoami, plugins, config
dn: cn=whoami,cn=plugins,cn=config
cn: whoami
nsslapd-plugin-depends-on-type: database
nsslapd-pluginDescription: whoami extended operation plugin
nsslapd-pluginEnabled: on
nsslapd-pluginId: whoami-plugin
nsslapd-pluginInitfunc: whoami_init
nsslapd-pluginPath: libwhoami-plugin
nsslapd-pluginType: extendedop
nsslapd-pluginVendor: 389 Project
nsslapd-pluginVersion: 1.3.6.1
objectClass: top
objectClass: nsSlapdPlugin
objectClass: extensibleObject


Expected results:
If whoami plugin is enabled during IPA upgrade if it is not enabled.

Metadata Update from @pvomacka:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1484826

2 years ago

Metadata Update from @pvomacka:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1484826

2 years ago

Metadata Update from @pvomacka:
- Issue assigned to pvomacka

2 years ago

Metadata Update from @pvoborni:
- Issue priority set to: critical
- Issue set to the milestone: FreeIPA 4.5.4

2 years ago

Metadata Update from @pvomacka:
- Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/1010

2 years ago

master:

  • 45bd31b Adds whoami DS plugin in case that plugin is missing

ipa-4-5:

  • 736a472 Adds whoami DS plugin in case that plugin is missing

ipa-4-6:

  • 59ef33d Adds whoami DS plugin in case that plugin is missing

Metadata Update from @pvomacka:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

2 years ago

Login to comment on this ticket.

Metadata