[Freeipa-users] Re: ipa-healthcheck with fresh replica

2020-06-08 Thread Jochen Kellner via FreeIPA-users
Jochen Kellner via FreeIPA-users writes: > In IPA I have four certificates for "IPA RA" - one (the oldest) revoked, > two are expired in 2017 and 2019 and one valid until next year. > > The certificate in CS.cfg is expired: > > Serial Number: 268173317 (0xffc0005) > ... > Validity

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Karim Bourenane via FreeIPA-users
Thank you for your update As Florence says too, i have also only update ipa-*, but i have several Error: [Ensurung CA is using LDAPProfileSubsustem) [Migration certificat profiles to LDAP] IPA server upgrade failed : Inspect /var/log/ipaupgrade.log and run command ipa-upgrade manually. Unexpe

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Rob Crittenden via FreeIPA-users
Karim Bourenane via FreeIPA-users wrote: > Hello François, All > > Thanks you for your answer / update > > Here's what I did: > All process RUNNING with : ipactl status > yum update > > *I have several error into the yum update command *: > 2020-06-08T09:39:42Z ERROR IPA server upgrade failed: I

[Freeipa-users] Re: Problem with AD users after upgrade

2020-06-08 Thread Rob Crittenden via FreeIPA-users
Ronald Wimmer via FreeIPA-users wrote: > On 05.06.20 17:33, Ronald Wimmer via FreeIPA-users wrote: >> On 05.06.20 16:24, Ronald Wimmer via FreeIPA-users wrote: >>> I did an IPA migration from CentOS 7 machines to OL 8.1 following the >>> procedure as documented in >>> https://access.redhat.com/docu

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Karim Bourenane via FreeIPA-users
Hello I found a track, its appear that the JAVA dont want to leave the TCPV6 port connexion: #netstat -plten | grep 8433 tcp6 0 0 :::8443 :::* LISTEN 17 178055 25551/java And also http with tcp6 443 This connexion launched if the command : yum update (come in libcc ) or when i launch ipa-ser

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Karim Bourenane via FreeIPA-users
This process number : 25551, its launched by pkiuser for pki-tomcat service. Bien à vous Mr Karim Bourenane +33686464439 +32 493 86 63 54 Le lun. 8 juin 2020 à 16:25, Karim Bourenane a écrit : > Hello > > I found a track, its appear that the JAVA dont want to leave the TCPV6 > port connexion

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Karim Bourenane via FreeIPA-users
Hello François, Florence, All After checking and disabling my local firewall. I have the same problem: [Ensurung CA is using LDAPProfileSubsustem) [Migration certificat profiles to LDAP] IPA server upgrade failed : Inspect /var/log/ipaupgrade.log and run command ipa-upgrade manually. Unexpect

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Karim Bourenane via FreeIPA-users
Hello François, All Thanks you for your answer / update Here's what I did: All process RUNNING with : ipactl status yum update *I have several error into the yum update command *: 2020-06-08T09:39:42Z ERROR IPA server upgrade failed: Inspect /var/log/ipaupgrade.log and run command ipa-server-upg

[Freeipa-users] Re: Planing multi-site deployment

2020-06-08 Thread Willie Lima via FreeIPA-users
Thank you for replying. Now I understand that concept, It worked for me. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://do

[Freeipa-users] Trust controllers vs. trust agents

2020-06-08 Thread Ronald Wimmer via FreeIPA-users
After an IPA upgrade all of my 8 IPA servers are trust controllers. Before the upgrade only half of them were trust controllers. The other half were trust agents. In my opinion not all of them have to be trust controllers. Is it safe to remove the controller role on 4 of the 8 servers? If yes,

[Freeipa-users] Re: Problem with AD users after upgrade

2020-06-08 Thread Ronald Wimmer via FreeIPA-users
On 05.06.20 17:33, Ronald Wimmer via FreeIPA-users wrote: On 05.06.20 16:24, Ronald Wimmer via FreeIPA-users wrote: I did an IPA migration from CentOS 7 machines to OL 8.1 following the procedure as documented in https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/inst