Bug 1776930
| Summary: | Enabling DNS proxy feature on Red Hat Satellite 6.6 is failing | ||
|---|---|---|---|
| Product: | Red Hat Satellite | Reporter: | Anand Jambhulkar <ajambhul> |
| Component: | Documentation | Assignee: | Marie Hornickova <mdolezel> |
| Documentation sub component: | default | QA Contact: | |
| Status: | CLOSED CURRENTRELEASE | Docs Contact: | |
| Severity: | high | ||
| Priority: | unspecified | CC: | aruzicka, ehelms, ekohlvan, inecas, ryandeussing, sokeeffe, sshtein, vsedmik |
| Version: | 6.6.0 | Keywords: | Reopened, Triaged |
| Target Milestone: | Unspecified | ||
| Target Release: | Unused | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | installing-capsule | ||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-12-21 17:41:20 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Anand Jambhulkar
2019-11-26 15:28:42 UTC
Hello Eric, The customer has resolved the issue which was due to the incorrect permissions on "rndc.key" file. The customer provided the following response - " The used Article (https://access.redhat.com/documentation/en-us/red_hat_satellite/6.6/html/installing_capsule_server/configuring_external_services) is not for Red Hat IDM integration and I could integrate IDM with this Article (https://access.redhat.com/documentation/en-us/red_hat_satellite/6.6/html/administering_red_hat_satellite/chap-red_hat_satellite-administering_red_hat_satellite-configuring_external_authentication#sect-Red_Hat_Satellite-Administering_Red_Hat_Satellite-Configuring_External_Authentication-Using_Identity_Management) successfully. Sadly there are multiple documentations from Red Hat about similar use cases which are different and confusing. Also the Issue of the failing satellite-installer was because of wrong Permission of the "rndc.key" (https://bugzilla.redhat.com/show_bug.cgi?id=1776930), which had sadly no hint in the Satellite Logs. " Thanks and Regards, Anand Jambhulkar We moved this because the installer only points to the file and doesn't manage it. For local installations we ensure foreman-proxy is in the named group because both need to read the file. In this remote case we do have a a validate_readable to ensure it's readable. https://github.com/theforeman/smart-proxy/blob/9804512b133bfbc99e1d0d3dbf34e3971e6057bc/modules/dns_nsupdate/dns_nsupdate_plugin.rb#L9 That means the logs should already report it's failing. In this case it looks like the configuring_external_services document should actually recommend to set the group to foreman-proxy instead of named. (In reply to Anand Jambhulkar from comment #4) > Also the Issue of the failing satellite-installer was because of wrong > Permission of the "rndc.key" > (https://bugzilla.redhat.com/show_bug.cgi?id=1776930), which had sadly no > hint in the Satellite Logs. There should have been in /var/log/foreman-proxy/proxy.log Thank you for your interest in Satellite 6. We have evaluated this request, and while we recognize that it is a valid request, we do not expect this to be implemented in the product in the foreseeable future. This is due to other priorities for the product, and not a reflection on the request itself. We are therefore closing this out as WONTFIX. If you have any concerns about this feel free to contact your Red Hat Account Team. Thank you. For what it's worth, I actually think this is still relevant. It should have been triaged as a documentation bug. In https://github.com/theforeman/foreman-documentation/pull/498#pullrequestreview-640968680 I gave detailed instructions what should be done instead. The upstream PR has been merged. |