<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>33463</bug_id>
          
          <creation_ts>2017-05-10 16:34:13 +0300</creation_ts>
          <short_desc>Ошибка обновления FreeIPA Server</short_desc>
          <delta_ts>2017-05-16 16:07:58 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>3</classification_id>
          <classification>Distributions</classification>
          <product>Branch p8</product>
          <component>freeipa-server</component>
          <version>не указана</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sergey Novikov">sotor</reporter>
          <assigned_to name="Andrey Cherepanov">cas</assigned_to>
          <cc>aen</cc>
    
    <cc>boyarsh</cc>
    
    <cc>cas</cc>
    
    <cc>rider</cc>
          
          <qa_contact name="qa-p8@altlinux.org">qa-p8</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>163610</commentid>
    <comment_count>0</comment_count>
    <who name="Sergey Novikov">sotor</who>
    <bug_when>2017-05-10 16:34:13 +0300</bug_when>
    <thetext>Обновление сервера FreeIPA падает с ошибкой:
# ipa-server-upgrade
session memcached servers not running
Upgrading IPA:
  [1/8]: saving configuration
  [2/8]: disabling listeners
  [3/8]: enabling DS global lock
  [4/8]: starting directory server
  [5/8]: updating schema
  [6/8]: upgrading server
  [7/8]: stopping directory server
  [8/8]: restoring configuration
Done.
Update complete
Upgrading IPA services
Upgrading the configuration of the IPA services
[Verifying that root certificate is published]
[Migrate CRL publish directory]
Publish directory already set to new location
/etc/dirsrv/slapd-IPA-BASEALT-RU/certmap.conf is now managed by IPA. It will be overwritten. A backup of the original will be made.
[Verifying that CA proxy configuration is correct]
[Verifying that KDC configuration is using ipa-kdb backend]
[Fix DS schema file syntax]
[Removing RA cert from DS NSS database]
[Enable sidgen and extdom plugins by default]
[Updating mod_nss protocol versions]
[Updating mod_nss cipher suite]
[Fixing trust flags in /etc/httpd2/conf/nss]
[Exporting KRA agent PEM file]
KRA is not enabled
[Removing self-signed CA]
[Removing Dogtag 9 CA]
Configuring DNS key synchronization service (ipa-dnskeysyncd)
  [1/7]: checking status
  [error] RuntimeError: OpenDNSSEC UID not found
IPA server upgrade failed: Inspect /var/log/ipaupgrade.log and run command ipa-server-upgrade manually.
OpenDNSSEC UID not found
The ipa-server-upgrade command failed. See /var/log/ipaupgrade.log for more information

Версия до обновления:
# rpm -qa |grep freeipa
python-module-freeipa-4.3.2-alt8.M80P.1
freeipa-server-common-4.3.2-alt8.M80P.1
freeipa-client-4.3.2-alt8.M80P.1
freeipa-server-4.3.2-alt8.M80P.1
freeipa-client-common-4.3.2-alt8.M80P.1
freeipa-admintools-4.3.2-alt8.M80P.1
freeipa-common-4.3.2-alt8.M80P.1
freeipa-server-dns-4.3.2-alt8.M80P.1

Версия после обновления:
# rpm -qa |grep freeipa
freeipa-client-4.3.3-alt1.M80P.1
freeipa-client-common-4.3.3-alt1.M80P.1
freeipa-server-4.3.3-alt1.M80P.1
freeipa-server-common-4.3.3-alt1.M80P.1
python-module-freeipa-4.3.3-alt1.M80P.1
freeipa-server-dns-4.3.3-alt1.M80P.1
freeipa-common-4.3.3-alt1.M80P.1
freeipa-admintools-4.3.3-alt1.M80P.1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>163612</commentid>
    <comment_count>1</comment_count>
    <who name="Anton Farygin">rider</who>
    <bug_when>2017-05-10 16:45:18 +0300</bug_when>
    <thetext>Воспроизводится на стенде.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>163614</commentid>
    <comment_count>2</comment_count>
    <who name="Mikhail Efremov">sem</who>
    <bug_when>2017-05-10 18:13:30 +0300</bug_when>
    <thetext>Я вообще не пробовал запускать эту команду и не думаю, что она необходима при данном обновлении. Там нет изменений конфигурации, которые бы требовалось как-то обрабатывать, что и пытается делать этот скрипт.
DNSSEC я там тоже оторву, конечно, но это никак не блокер.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>163615</commentid>
    <comment_count>3</comment_count>
    <who name="Sergey Novikov">sotor</who>
    <bug_when>2017-05-10 18:14:54 +0300</bug_when>
    <thetext>После обновления сервис IPA не стартует и просит выполнить команду ipa-server-upgrade</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>163617</commentid>
    <comment_count>4</comment_count>
    <who name="Mikhail Efremov">sem</who>
    <bug_when>2017-05-10 21:03:08 +0300</bug_when>
    <thetext>Да, он проверяет версию при старте, похоже. Можно конечно пока оторвать проверку, но тогда уж лучше сразу чинить ipa-server-upgrade, в будущем все равно понадобится.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>163703</commentid>
    <comment_count>5</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2017-05-16 16:07:58 +0300</bug_when>
    <thetext>freeipa-4.3.3-alt3 -&gt; sisyphus:

Tue May 16 2017 Mikhail Efremov &lt;sem@altlinux.org&gt; 4.3.3-alt3
- server: Require pki-kra.
- Run ipa-server-upgrade at package update.
- Add ipa_configured script.
- Fix ipa-server-upgrade (closes: #33463).
- Set JAVA_STACK_SIZE to 8m.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>