#8281 Nightly test failure in ipa-4-6: test_integration/test_installation.py::TestInstallWithCA_KRA1::()::test_replica0_ipa_ca_install
Closed: worksforme a month ago by pcech. Opened 3 months ago by frenaud.

The ipa-4-6 nightly test test_integration/test_installation.py::TestInstallWithCA_KRA1::()::test_replica0_ipa_ca_install failed in PR 4556 while installing a CA clone on a replica.
Logs available at the following location


ipa-ca-install failed while restarting ds:

2020-04-19T16:01:25Z DEBUG Starting external process
2020-04-19T16:01:25Z DEBUG args=/bin/systemctl restart dirsrv@IPA-TEST.service
2020-04-19T16:01:32Z DEBUG Process finished, return code=1
2020-04-19T16:01:32Z DEBUG stdout=
2020-04-19T16:01:32Z DEBUG stderr=Job for dirsrv@IPA-TEST.service failed because the service did not take the steps required by its unit configuration.
See "systemctl  status dirsrv@IPA-TEST.service" and "journalctl  -xe" for details.

2020-04-19T16:01:32Z DEBUG   File "/usr/lib/python3.6/site-packages/ipaserver/install/installutils.py", line 1015, in run_script
    return_value = main_function()

  File "/usr/sbin/ipa-ca-install", line 341, in main
    promote(safe_options, options, filename)

  File "/usr/sbin/ipa-ca-install", line 309, in promote
    install_replica(safe_options, options, filename)

  File "/usr/sbin/ipa-ca-install", line 233, in install_replica
    ca.install(True, config, options, custodia=custodia)

  File "/usr/lib/python3.6/site-packages/ipaserver/install/ca.py", line 255, in install
    install_step_1(standalone, replica_config, options, custodia=custodia)

  File "/usr/lib/python3.6/site-packages/ipaserver/install/ca.py", line 389, in install_step_1
    installutils.restart_dirsrv()

  File "/usr/lib/python3.6/site-packages/ipaserver/install/installutils.py", line 1642, in restart_dirsrv
    wait=True, ldapi=True)

  File "/usr/lib/python3.6/site-packages/ipaplatform/redhat/services.py", line 130, in restart
    instance_name, capture_output=capture_output, wait=wait)

  File "/usr/lib/python3.6/site-packages/ipaplatform/base/services.py", line 336, in restart
    capture_output, wait)

  File "/usr/lib/python3.6/site-packages/ipaplatform/base/services.py", line 322, in _restart_base
    skip_output=not capture_output)

  File "/usr/lib/python3.6/site-packages/ipapython/ipautil.py", line 563, in run
    raise CalledProcessError(p.returncode, arg_string, str(output))

2020-04-19T16:01:32Z DEBUG The ipa-ca-install command failed, exception: CalledProcessError: Command '/bin/systemctl restart dirsrv@IPA-TEST.service' returned non-zero exit status 1.

dirsrv error log contains the following logs:

[19/Apr/2020:16:01:32.357398078 +0000] - ERR - cos-plugin - cos_dn_defs_cb - Skipping CoS Definition cn=Password Policy,cn=accounts,dc=ipa,dc=test--no CoS Templates found, which should be added before the CoS Definition.
[19/Apr/2020:16:01:32.404634864 +0000] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/replica0.ipa.test@IPA.TEST] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328324 (Generic error (see e-text))
[19/Apr/2020:16:01:32.412942328 +0000] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/replica0.ipa.test@IPA.TEST] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328324 (Generic error (see e-text))

and the journal :

Apr 19 16:01:32 replica0.ipa.test ns-slapd[20486]: [19/Apr/2020:16:01:32.404021834 +0000] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/replica0.ipa.test@IPA.TEST] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328324 (Generic error (see e-text))
Apr 19 16:01:32 replica0.ipa.test ns-slapd[20486]: [19/Apr/2020:16:01:32.412913851 +0000] - ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/replica0.ipa.test@IPA.TEST] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328324 (Generic error (see e-text))
Apr 19 16:01:32 replica0.ipa.test ns-slapd[20486]: GSSAPI client step 1
Apr 19 16:01:32 replica0.ipa.test ns-slapd[20486]: GSSAPI client step 1
Apr 19 16:01:32 replica0.ipa.test ns-slapd[20486]: GSSAPI client step 1
Apr 19 16:01:32 replica0.ipa.test ns-slapd[20486]: GSSAPI client step 1
Apr 19 16:01:32 replica0.ipa.test ns-slapd[20486]: Inconsistency detected by ld.so: ../elf/dl-tls.c: 488: _dl_allocate_tls_init: Assertion `listp->slotinfo[cnt].gen <= GL(dl_tls_generation)' failed!
Apr 19 16:01:32 replica0.ipa.test ns-slapd[20486]: GSSAPI Error: Unspecified GSS failure.  Minor code may provide more information (No Kerberos credentials available (default cache: /tmp/krb5cc_389))

The issue happened only once, keep it open in case it re-occurs but don't start working on it yet.

No evidence of a bug, so I am closing it.

Metadata Update from @pcech:
- Issue close_status updated to: worksforme
- Issue status updated to: Closed (was: Open)

a month ago

Login to comment on this ticket.

Metadata