Discussion:
[Freeipa-users] ipa server-del
Ian Harding
2017-05-03 22:41:32 UTC
Permalink
Is there any way this can be made to work? This server does not exist
in real life or seemingly in FreeIPA, but a ghost of it does.

***@vm-ian-laptop:~$ ipa server-find freeipa-dal.bpt.rocks
--------------------
1 IPA server matched
--------------------
Server name: freeipa-dal.bpt.rocks
Min domain level: 0
Max domain level: 0
----------------------------
Number of entries returned 1
----------------------------
***@vm-ian-laptop:~$ ipa server-del freeipa-dal.bpt.rocks
Removing freeipa-dal.bpt.rocks from replication topology, please wait...
ipa: ERROR: freeipa-dal.bpt.rocks: server not found
***@vm-ian-laptop:~$ ipa server-del freeipa-dal.bpt.rocks --force
Removing freeipa-dal.bpt.rocks from replication topology, please wait...
ipa: ERROR: freeipa-dal.bpt.rocks: server not found
***@vm-ian-laptop:~$ ipa server-del freeipa-dal.bpt.rocks --force
--continue
Removing freeipa-dal.bpt.rocks from replication topology, please wait...
ipa: WARNING: Forcing removal of freeipa-dal.bpt.rocks
---------------------
Deleted IPA server ""
---------------------
Failed to remove: freeipa-dal.bpt.rocks
***@vm-ian-laptop:~$

- Ian
--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project
Petr Vobornik
2017-05-04 11:35:45 UTC
Permalink
Post by Ian Harding
Is there any way this can be made to work? This server does not exist
in real life or seemingly in FreeIPA, but a ghost of it does.
--------------------
1 IPA server matched
--------------------
Server name: freeipa-dal.bpt.rocks
Min domain level: 0
Max domain level: 0
----------------------------
Number of entries returned 1
----------------------------
Removing freeipa-dal.bpt.rocks from replication topology, please wait...
ipa: ERROR: freeipa-dal.bpt.rocks: server not found
Removing freeipa-dal.bpt.rocks from replication topology, please wait...
ipa: ERROR: freeipa-dal.bpt.rocks: server not found
--continue
Removing freeipa-dal.bpt.rocks from replication topology, please wait...
ipa: WARNING: Forcing removal of freeipa-dal.bpt.rocks
---------------------
Deleted IPA server ""
---------------------
Failed to remove: freeipa-dal.bpt.rocks
- Ian
This looks like a bug to me.

Probably some LDAP search ended with "not found" result which then was
incorrectly interpreted as "server not found".

To know where the issue is it would help switch IPA framework on server
to debug mode [1] and provide httpd/error_log and dirsrv/$domain/access
log from time of execution of the command.

[1] https://www.freeipa.org/page/Troubleshooting#Administration_Framework
--
Petr Vobornik
--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project
Rob Crittenden
2017-05-04 13:13:58 UTC
Permalink
Post by Petr Vobornik
Post by Ian Harding
Is there any way this can be made to work? This server does not exist
in real life or seemingly in FreeIPA, but a ghost of it does.
--------------------
1 IPA server matched
--------------------
Server name: freeipa-dal.bpt.rocks
Min domain level: 0
Max domain level: 0
----------------------------
Number of entries returned 1
----------------------------
Removing freeipa-dal.bpt.rocks from replication topology, please wait...
ipa: ERROR: freeipa-dal.bpt.rocks: server not found
Removing freeipa-dal.bpt.rocks from replication topology, please wait...
ipa: ERROR: freeipa-dal.bpt.rocks: server not found
--continue
Removing freeipa-dal.bpt.rocks from replication topology, please wait...
ipa: WARNING: Forcing removal of freeipa-dal.bpt.rocks
---------------------
Deleted IPA server ""
---------------------
Failed to remove: freeipa-dal.bpt.rocks
- Ian
This looks like a bug to me.
Probably some LDAP search ended with "not found" result which then was
incorrectly interpreted as "server not found".
To know where the issue is it would help switch IPA framework on server
to debug mode [1] and provide httpd/error_log and dirsrv/$domain/access
log from time of execution of the command.
[1] https://www.freeipa.org/page/Troubleshooting#Administration_Framework
I think it is probably a replication conflict entry. I'd start with
https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/8.2/html/Administration_Guide/Managing_Replication-Solving_Common_Replication_Conflicts.html

rob
--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project
Loading...