Bug 33538 - ipa-server-install завершается ошибкой.
Summary: ipa-server-install завершается ошибкой.
Status: CLOSED FIXED
Alias: None
Product: Branch p8
Classification: Distributions
Component: freeipa-server (show other bugs)
Version: не указана
Hardware: all Linux
: P3 normal
Assignee: Andrey Cherepanov
QA Contact: qa-p8@altlinux.org
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-06-09 11:35 MSK by Bolshedvorsky Evgeny
Modified: 2017-08-10 16:48 MSK (History)
0 users

See Also:


Attachments
/var/log/ipaserver-install.log (33.00 KB, application/gzip)
2017-06-09 11:36 MSK, Bolshedvorsky Evgeny
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Bolshedvorsky Evgeny 2017-06-09 11:35:23 MSK
Чистый p8 с минимальной установке.
сделал apt-get update и dist-upgrade

Следую по инструкции с wiki
https://www.altlinux.org/FreeIPA#.D0.A3.D1.81.D1.82.D0.B0.D0.BD.D0.BE.D0.B2.D0.BA.D0.B0_.D1.81.D0.B5.D1.80.D0.B2.D0.B5.D1.80.D0.B0_FreeIPA


По ходу усановки падает: 
 ipa-server-install -U --hostname=$(hostname) -r EXAMPLE.TEST -n example.test -p 12345678 -a 12345678 --setup-dns --no-forwarders --no-reverse

Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes 30 seconds
  [1/28]: creating certificate server user
  [2/28]: configuring certificate server instance
  [3/28]: stopping certificate server instance to update CS.cfg
  [4/28]: backing up CS.cfg
  [5/28]: disabling nonces
  [6/28]: set up CRL publishing
  [7/28]: enable PKIX certificate path discovery and validation
  [8/28]: starting certificate server instance
ipa.ipaserver.install.cainstance.CAInstance: CRITICAL Failed to restart the Dogtag instance.See the installation log for details.
  [9/28]: creating RA agent certificate database
  [10/28]: importing CA chain to RA certificate database
  [error] RuntimeError: Unable to retrieve CA chain: request failed with HTTP status 500
ipa.ipapython.install.cli.install_tool(Server): ERROR    Unable to retrieve CA chain: request failed with HTTP status 500
ipa.ipapython.install.cli.install_tool(Server): ERROR    The ipa-server-install command failed. See /var/log/ipaserver-install.log for more information
Comment 1 Bolshedvorsky Evgeny 2017-06-09 11:36:50 MSK
Created attachment 7105 [details]
/var/log/ipaserver-install.log
Comment 2 Bolshedvorsky Evgeny 2017-06-09 15:00:47 MSK
В сизифе такая-же проблема.
Comment 3 Bolshedvorsky Evgeny 2017-06-16 18:20:55 MSK
Поставил p8 server в дефолтной установке без dist-upgrade.

java ругается 500 ошибкой, из-за недоступности ns-slapd который получил  +++ killed by SIGABRT +++.
Если в этот момент запустить dirsrv и перезапустить pki-tomcatd.target, то установка продолжается, но дальше получаем: 
ns-slapd[18891]: segfault at 55d ip 00000000004169a3 sp 00007f29f07f7bd0 error 4 in ns-slapd[400000+5a000]
Comment 4 Repository Robot 2017-08-10 16:48:47 MSK
freeipa-4.3.3-alt4 -> sisyphus:

Thu Aug 10 2017 Mikhail Efremov <sem@altlinux.org> 4.3.3-alt4
- Add %apache_conf_dir macro.
- Move ipa_configured script to server-common subpackage.
- Init argument for slapi_pblock_get() (closes: #33538).
- Fix httpd2 configuration (closes: #33513, #33466).