Login
[x]
Log in using an account from:
Fedora Account System
Red Hat Associate
Red Hat Customer
Or login using a Red Hat Bugzilla account
Forgot Password
Login:
Hide Forgot
Create an Account
Red Hat Bugzilla – Attachment 1472641 Details for
Bug 1602410
IPA client installtion fails with error " KerberosError: No valid Negotiate header in server response".
[?]
New
Simple Search
Advanced Search
My Links
Browse
Requests
Reports
Current State
Search
Tabular reports
Graphical reports
Duplicates
Other Reports
User Changes
Plotly Reports
Bug Status
Bug Severity
Non-Defaults
|
Product Dashboard
Help
Page Help!
Bug Writing Guidelines
What's new
Browser Support Policy
5.0.4.rh83 Release notes
FAQ
Guides index
User guide
Web Services
Contact
Legal
This site requires JavaScript to be enabled to function correctly, please enable it.
IPA client install log 02/08
ipaclient-install.log (text/plain), 17.24 KB, created by
Gaurav Swami
on 2018-08-02 09:59:39 UTC
(
hide
)
Description:
IPA client install log 02/08
Filename:
MIME Type:
Creator:
Gaurav Swami
Created:
2018-08-02 09:59:39 UTC
Size:
17.24 KB
patch
obsolete
>2018-07-30T06:32:05Z DEBUG Logging to /var/log/ipaclient-install.log >2018-07-30T06:32:05Z DEBUG ipa-client-install was invoked with arguments [] and options: {'no_dns_sshfp': False, 'force': False, 'verbose': True, 'ip_addresses': None, 'configure_firefox': False, 'realm_name': 'COMVERSE.COM', 'force_ntpd': False, 'on_master': False, 'no_nisdomain': False, 'ssh_trust_dns': False, 'principal': 'admin', 'keytab': None, 'no_ntp': True, 'domain_name': 'comverse.com', 'request_cert': False, 'fixed_primary': False, 'no_ac': False, 'no_sudo': False, 'ca_cert_files': None, 'all_ip_addresses': False, 'kinit_attempts': None, 'ntp_servers': None, 'enable_dns_updates': False, 'no_sshd': False, 'no_sssd': False, 'no_krb5_offline_passwords': False, 'servers': ['ntp-ipaserver.comverse.com'], 'no_ssh': False, 'force_join': False, 'firefox_dir': None, 'unattended': True, 'quiet': False, 'nisdomain': None, 'prompt_password': False, 'host_name': None, 'permit': False, 'automount_location': None, 'preserve_sssd': False, 'mkhomedir': True, 'log_file': None, 'uninstall': False} >2018-07-30T06:32:05Z DEBUG IPA version 4.5.4-10.el7_5.3 >2018-07-30T06:32:05Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' >2018-07-30T06:32:05Z DEBUG Starting external process >2018-07-30T06:32:05Z DEBUG args=/usr/sbin/selinuxenabled >2018-07-30T06:32:05Z DEBUG Process finished, return code=0 >2018-07-30T06:32:05Z DEBUG stdout= >2018-07-30T06:32:05Z DEBUG stderr= >2018-07-30T06:32:05Z DEBUG [IPA Discovery] >2018-07-30T06:32:05Z DEBUG Starting IPA discovery with domain=comverse.com, servers=['ntp-ipaserver.comverse.com'], hostname=rnd-vm-11-246.cz.intinfra.com >2018-07-30T06:32:05Z DEBUG Server and domain forced >2018-07-30T06:32:05Z DEBUG [Kerberos realm search] >2018-07-30T06:32:05Z DEBUG Kerberos realm forced >2018-07-30T06:32:05Z DEBUG [LDAP server check] >2018-07-30T06:32:05Z DEBUG Verifying that ntp-ipaserver.comverse.com (realm COMVERSE.COM) is an IPA server >2018-07-30T06:32:05Z DEBUG Init LDAP connection to: ldap://ntp-ipaserver.comverse.com:389 >2018-07-30T06:32:05Z DEBUG Search LDAP server for IPA base DN >2018-07-30T06:32:06Z DEBUG Check if naming context 'dc=comverse,dc=com' is for IPA >2018-07-30T06:32:06Z DEBUG LDAP Error: Anonymous access not allowed >2018-07-30T06:32:06Z DEBUG Generated basedn from realm: dc=comverse,dc=com >2018-07-30T06:32:06Z DEBUG Discovery result: NO_ACCESS_TO_LDAP; server=None, domain=comverse.com, kdc=ntp-ipaserver.comverse.com, basedn=dc=comverse,dc=com >2018-07-30T06:32:06Z DEBUG Validated servers: ntp-ipaserver.comverse.com >2018-07-30T06:32:06Z DEBUG will use discovered domain: comverse.com >2018-07-30T06:32:06Z DEBUG Using servers from command line, disabling DNS discovery >2018-07-30T06:32:06Z DEBUG will use provided server: ntp-ipaserver.comverse.com >2018-07-30T06:32:06Z DEBUG will use discovered realm: COMVERSE.COM >2018-07-30T06:32:06Z DEBUG will use discovered basedn: dc=comverse,dc=com >2018-07-30T06:32:06Z INFO Client hostname: rnd-vm-11-246.cz.intinfra.com >2018-07-30T06:32:06Z DEBUG Hostname source: Machine's FQDN >2018-07-30T06:32:06Z INFO Realm: COMVERSE.COM >2018-07-30T06:32:06Z DEBUG Realm source: Forced >2018-07-30T06:32:06Z INFO DNS Domain: comverse.com >2018-07-30T06:32:06Z DEBUG DNS Domain source: Forced >2018-07-30T06:32:06Z INFO IPA Server: ntp-ipaserver.comverse.com >2018-07-30T06:32:06Z DEBUG IPA Server source: Provided as option >2018-07-30T06:32:06Z INFO BaseDN: dc=comverse,dc=com >2018-07-30T06:32:06Z DEBUG BaseDN source: Generated from Kerberos realm >2018-07-30T06:32:06Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' >2018-07-30T06:32:06Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state' >2018-07-30T06:32:06Z DEBUG Starting external process >2018-07-30T06:32:06Z DEBUG args=/usr/sbin/ipa-rmkeytab -k /etc/krb5.keytab -r COMVERSE.COM >2018-07-30T06:32:06Z DEBUG Process finished, return code=5 >2018-07-30T06:32:06Z DEBUG stdout= >2018-07-30T06:32:06Z DEBUG stderr=realm not found > >2018-07-30T06:32:06Z INFO Skipping synchronizing time with NTP server. >2018-07-30T06:32:06Z DEBUG Starting external process >2018-07-30T06:32:06Z DEBUG args=keyctl get_persistent @s 0 >2018-07-30T06:32:06Z DEBUG Process finished, return code=0 >2018-07-30T06:32:06Z DEBUG stdout=33639885 > >2018-07-30T06:32:06Z DEBUG stderr= >2018-07-30T06:32:06Z DEBUG Enabling persistent keyring CCACHE >2018-07-30T06:32:06Z DEBUG Writing Kerberos configuration to /tmp/tmpMw1EM8: >2018-07-30T06:32:06Z DEBUG #File modified by ipa-client-install > >includedir /etc/krb5.conf.d/ >includedir /var/lib/sss/pubconf/krb5.include.d/ > >[libdefaults] > default_realm = COMVERSE.COM > dns_lookup_realm = false > dns_lookup_kdc = false > rdns = false > dns_canonicalize_hostname = false > ticket_lifetime = 24h > forwardable = true > udp_preference_limit = 0 > default_ccache_name = KEYRING:persistent:%{uid} > > >[realms] > COMVERSE.COM = { > kdc = ntp-ipaserver.comverse.com:88 > master_kdc = ntp-ipaserver.comverse.com:88 > admin_server = ntp-ipaserver.comverse.com:749 > kpasswd_server = ntp-ipaserver.comverse.com:464 > default_domain = comverse.com > pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem > pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem > > } > > >[domain_realm] > .comverse.com = COMVERSE.COM > comverse.com = COMVERSE.COM > rnd-vm-11-246.cz.intinfra.com = COMVERSE.COM > .cz.intinfra.com = COMVERSE.COM > cz.intinfra.com = COMVERSE.COM > > > >2018-07-30T06:32:06Z DEBUG Initializing principal admin@COMVERSE.COM using password >2018-07-30T06:32:06Z DEBUG Starting external process >2018-07-30T06:32:06Z DEBUG args=/usr/bin/kinit admin@COMVERSE.COM -c /tmp/krbccqyjVw9/ccache >2018-07-30T06:32:06Z DEBUG Process finished, return code=0 >2018-07-30T06:32:06Z DEBUG stdout=Password for admin@COMVERSE.COM: > >2018-07-30T06:32:06Z DEBUG stderr= >2018-07-30T06:32:06Z DEBUG trying to retrieve CA cert via LDAP from ntp-ipaserver.comverse.com >2018-07-30T06:32:07Z DEBUG retrieving schema for SchemaCache url=ldap://ntp-ipaserver.comverse.com:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x7f6ca7a9a1b8> >2018-07-30T06:32:07Z INFO Successfully retrieved CA cert > Subject: CN=Certificate Authority,O=COMVERSE.COM > Issuer: CN=Certificate Authority,O=COMVERSE.COM > Valid From: 2018-02-22 09:41:24 > Valid Until: 2038-02-22 09:41:24 > >2018-07-30T06:32:07Z DEBUG Starting external process >2018-07-30T06:32:07Z DEBUG args=/usr/sbin/ipa-join -s ntp-ipaserver.comverse.com -b dc=comverse,dc=com -h rnd-vm-11-246.cz.intinfra.com >2018-07-30T06:32:10Z DEBUG Process finished, return code=0 >2018-07-30T06:32:10Z DEBUG stdout= >2018-07-30T06:32:10Z DEBUG stderr=Failed to parse result: unsupported extended operation >Retrying with pre-4.0 keytab retrieval method... >Failed to retrieve encryption type Triple DES cbc mode with HMAC/sha1 (#16) >Failed to retrieve encryption type ArcFour with HMAC/md5 (#23) >Failed to retrieve encryption type Camellia-128 CTS mode with CMAC (#25) >Failed to retrieve encryption type Camellia-256 CTS mode with CMAC (#26) >Keytab successfully retrieved and stored in: /etc/krb5.keytab >Certificate subject base is: O=COMVERSE.COM > >2018-07-30T06:32:10Z INFO Enrolled in IPA realm COMVERSE.COM >2018-07-30T06:32:10Z DEBUG Starting external process >2018-07-30T06:32:10Z DEBUG args=kdestroy >2018-07-30T06:32:10Z DEBUG Process finished, return code=0 >2018-07-30T06:32:10Z DEBUG stdout= >2018-07-30T06:32:10Z DEBUG stderr= >2018-07-30T06:32:10Z DEBUG Initializing principal host/rnd-vm-11-246.cz.intinfra.com@COMVERSE.COM using keytab /etc/krb5.keytab >2018-07-30T06:32:10Z DEBUG using ccache /etc/ipa/.dns_ccache >2018-07-30T06:32:10Z DEBUG Attempt 1/5: success >2018-07-30T06:32:10Z DEBUG Backing up system configuration file '/etc/ipa/default.conf' >2018-07-30T06:32:10Z DEBUG -> Not backing up - '/etc/ipa/default.conf' doesn't exist >2018-07-30T06:32:10Z INFO Created /etc/ipa/default.conf >2018-07-30T06:32:10Z DEBUG Backing up system configuration file '/etc/sssd/sssd.conf' >2018-07-30T06:32:10Z DEBUG -> Not backing up - '/etc/sssd/sssd.conf' doesn't exist >2018-07-30T06:32:10Z INFO New SSSD config will be created >2018-07-30T06:32:10Z DEBUG Backing up system configuration file '/etc/nsswitch.conf' >2018-07-30T06:32:10Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' >2018-07-30T06:32:11Z INFO Configured sudoers in /etc/nsswitch.conf >2018-07-30T06:32:11Z INFO Configured /etc/sssd/sssd.conf >2018-07-30T06:32:11Z DEBUG Backing up system configuration file '/etc/krb5.conf' >2018-07-30T06:32:11Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index' >2018-07-30T06:32:11Z DEBUG Starting external process >2018-07-30T06:32:11Z DEBUG args=keyctl get_persistent @s 0 >2018-07-30T06:32:11Z DEBUG Process finished, return code=0 >2018-07-30T06:32:11Z DEBUG stdout=33639885 > >2018-07-30T06:32:11Z DEBUG stderr= >2018-07-30T06:32:11Z DEBUG Enabling persistent keyring CCACHE >2018-07-30T06:32:11Z DEBUG Writing Kerberos configuration to /etc/krb5.conf: >2018-07-30T06:32:11Z DEBUG #File modified by ipa-client-install > >includedir /etc/krb5.conf.d/ >includedir /var/lib/sss/pubconf/krb5.include.d/ > >[libdefaults] > default_realm = COMVERSE.COM > dns_lookup_realm = false > dns_lookup_kdc = false > rdns = false > dns_canonicalize_hostname = false > ticket_lifetime = 24h > forwardable = true > udp_preference_limit = 0 > default_ccache_name = KEYRING:persistent:%{uid} > > >[realms] > COMVERSE.COM = { > kdc = ntp-ipaserver.comverse.com:88 > master_kdc = ntp-ipaserver.comverse.com:88 > admin_server = ntp-ipaserver.comverse.com:749 > kpasswd_server = ntp-ipaserver.comverse.com:464 > default_domain = comverse.com > pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem > pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem > > } > > >[domain_realm] > .comverse.com = COMVERSE.COM > comverse.com = COMVERSE.COM > rnd-vm-11-246.cz.intinfra.com = COMVERSE.COM > .cz.intinfra.com = COMVERSE.COM > cz.intinfra.com = COMVERSE.COM > > > >2018-07-30T06:32:11Z INFO Configured /etc/krb5.conf for IPA realm COMVERSE.COM >2018-07-30T06:32:11Z DEBUG Starting external process >2018-07-30T06:32:11Z DEBUG args=/usr/bin/certutil -d /tmp/tmpEkhuvS -N -f /tmp/tmpEkhuvS/pwdfile.txt -f /tmp/tmpEkhuvS/pwdfile.txt >2018-07-30T06:32:11Z DEBUG Process finished, return code=0 >2018-07-30T06:32:11Z DEBUG stdout= >2018-07-30T06:32:11Z DEBUG stderr= >2018-07-30T06:32:11Z DEBUG Starting external process >2018-07-30T06:32:11Z DEBUG args=/usr/bin/certutil -d /tmp/tmpEkhuvS -A -n CA certificate 1 -t C,, -f /tmp/tmpEkhuvS/pwdfile.txt >2018-07-30T06:32:11Z DEBUG Process finished, return code=0 >2018-07-30T06:32:11Z DEBUG stdout= >2018-07-30T06:32:11Z DEBUG stderr= >2018-07-30T06:32:11Z DEBUG Error retrieving cookie from the persistent storage: expected string or buffer >2018-07-30T06:32:11Z DEBUG failed to find session_cookie in persistent storage for principal 'host/rnd-vm-11-246.cz.intinfra.com@COMVERSE.COM' >2018-07-30T06:32:11Z INFO trying https://ntp-ipaserver.comverse.com/ipa/json >2018-07-30T06:32:11Z DEBUG New HTTP connection (ntp-ipaserver.comverse.com) >2018-07-30T06:32:11Z DEBUG received Set-Cookie (<type 'list'>)'[]' >2018-07-30T06:32:11Z DEBUG Created connection context.rpcclient_140104608254736 >2018-07-30T06:32:11Z INFO [try 1]: Forwarding 'schema' to json server 'https://ntp-ipaserver.comverse.com/ipa/json' >2018-07-30T06:32:11Z DEBUG HTTP connection keep-alive (ntp-ipaserver.comverse.com) >2018-07-30T06:32:11Z DEBUG HTTP connection destroyed (ntp-ipaserver.comverse.com) >Traceback (most recent call last): > File "/usr/lib/python2.7/site-packages/ipalib/rpc.py", line 706, in single_request > if not self._auth_complete(response): > File "/usr/lib/python2.7/site-packages/ipalib/rpc.py", line 657, in _auth_complete > message=u"No valid Negotiate header in server response") >KerberosError: No valid Negotiate header in server response >2018-07-30T06:32:11Z DEBUG Destroyed connection context.rpcclient_140104608254736 >2018-07-30T06:32:11Z DEBUG File "/usr/lib/python2.7/site-packages/ipapython/admintool.py", line 172, in execute > return_value = self.run() > File "/usr/lib/python2.7/site-packages/ipapython/install/cli.py", line 333, in run > cfgr.run() > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 368, in run > self.execute() > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 392, in execute > for _nothing in self._executor(): > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 434, in __runner > exc_handler(exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 463, in _handle_execute_exception > self._handle_exception(exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 453, in _handle_exception > six.reraise(*exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 424, in __runner > step() > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 421, in <lambda> > step = lambda: next(self.__gen) > File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from > six.reraise(*exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from > value = gen.send(prev_value) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 658, in _configure > next(executor) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 434, in __runner > exc_handler(exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 463, in _handle_execute_exception > self._handle_exception(exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 521, in _handle_exception > self.__parent._handle_exception(exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 453, in _handle_exception > six.reraise(*exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 518, in _handle_exception > super(ComponentBase, self)._handle_exception(exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 453, in _handle_exception > six.reraise(*exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 424, in __runner > step() > File "/usr/lib/python2.7/site-packages/ipapython/install/core.py", line 421, in <lambda> > step = lambda: next(self.__gen) > File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from > six.reraise(*exc_info) > File "/usr/lib/python2.7/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from > value = gen.send(prev_value) > File "/usr/lib/python2.7/site-packages/ipapython/install/common.py", line 63, in _install > for _nothing in self._installer(self.parent): > File "/usr/lib/python2.7/site-packages/ipaclient/install/client.py", line 3628, in main > install(self) > File "/usr/lib/python2.7/site-packages/ipaclient/install/client.py", line 2348, in install > _install(options) > File "/usr/lib/python2.7/site-packages/ipaclient/install/client.py", line 2694, in _install > api.finalize() > File "/usr/lib/python2.7/site-packages/ipalib/plugable.py", line 714, in finalize > self.__do_if_not_done('load_plugins') > File "/usr/lib/python2.7/site-packages/ipalib/plugable.py", line 421, in __do_if_not_done > getattr(self, name)() > File "/usr/lib/python2.7/site-packages/ipalib/plugable.py", line 592, in load_plugins > for package in self.packages: > File "/usr/lib/python2.7/site-packages/ipalib/__init__.py", line 948, in packages > ipaclient.remote_plugins.get_package(self), > File "/usr/lib/python2.7/site-packages/ipaclient/remote_plugins/__init__.py", line 126, in get_package > plugins = schema.get_package(server_info, client) > File "/usr/lib/python2.7/site-packages/ipaclient/remote_plugins/schema.py", line 537, in get_package > schema = Schema(client) > File "/usr/lib/python2.7/site-packages/ipaclient/remote_plugins/schema.py", line 385, in __init__ > fingerprint, ttl = self._fetch(client, ignore_cache=read_failed) > File "/usr/lib/python2.7/site-packages/ipaclient/remote_plugins/schema.py", line 410, in _fetch > schema = client.forward(u'schema', **kwargs)['result'] > File "/usr/lib/python2.7/site-packages/ipalib/rpc.py", line 1116, in forward > return self._call_command(command, params) > File "/usr/lib/python2.7/site-packages/ipalib/rpc.py", line 1092, in _call_command > return command(*params) > File "/usr/lib/python2.7/site-packages/ipalib/rpc.py", line 1246, in _call > return self.__request(name, args) > File "/usr/lib/python2.7/site-packages/ipalib/rpc.py", line 1213, in __request > verbose=self.__verbose >= 3, > File "/usr/lib64/python2.7/xmlrpclib.py", line 1273, in request > return self.single_request(host, handler, request_body, verbose) > File "/usr/lib/python2.7/site-packages/ipalib/rpc.py", line 706, in single_request > if not self._auth_complete(response): > File "/usr/lib/python2.7/site-packages/ipalib/rpc.py", line 657, in _auth_complete > message=u"No valid Negotiate header in server response") > >2018-07-30T06:32:11Z DEBUG The ipa-client-install command failed, exception: KerberosError: No valid Negotiate header in server response >2018-07-30T06:32:11Z ERROR No valid Negotiate header in server response >2018-07-30T06:32:11Z ERROR The ipa-client-install command failed. See /var/log/ipaclient-install.log for more information
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 1602410
:
1460010
|
1472640
| 1472641 |
1473859
|
1473860
|
1482008
|
1482330
|
1483315
|
1483316
|
1483319
|
1483320