Bug 878168
Summary: | ipa trust-add fails with CIFS server communication error: code | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | Scott Poore <spoore> | ||||||
Component: | Documentation | Assignee: | Eliska Slobodova <eslobodo> | ||||||
Status: | CLOSED CURRENTRELEASE | QA Contact: | ecs-bugs | ||||||
Severity: | unspecified | Docs Contact: | |||||||
Priority: | unspecified | ||||||||
Version: | 6.4 | CC: | abokovoy, arubin, chhudson, dpal, mkosek, nkarandi, sbose, ssorce | ||||||
Target Milestone: | rc | Keywords: | Documentation, Reopened | ||||||
Target Release: | --- | ||||||||
Hardware: | Unspecified | ||||||||
OS: | Unspecified | ||||||||
Whiteboard: | |||||||||
Fixed In Version: | Doc Type: | Known Issue | |||||||
Doc Text: |
If configured, the Active Directory (AD) DNS server returns IPv4 and IPv6 addresses of an AD server. If the FreeIPA server cannot connect to the AD server with an IPv6 address, running the ipa trust-add command will fail even if it would be possible to use IPv4. To work around this problem, add the IPv4 address of the AD server to the /etc/hosts file. In this case, the FreeIPA server will use only the IPv4 address and executing ipa trust-add will be successful.
|
Story Points: | --- | ||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2013-06-26 12:09:49 UTC | Type: | Bug | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Embargoed: | |||||||||
Attachments: |
|
Description
Scott Poore
2012-11-19 19:22:54 UTC
It would be good to see logs taken from the affected system. 1. Add 'log level = 11' to /usr/share/ipa/smb.conf.empty 2. Retry. I've seen this error only once when the AD server wasn't able to resolve the IPA domain. If this is not the case in your setup maybe the AD server is confused in other way, maybe a reboot of the AD server helps? Upstream ticket: https://fedorahosted.org/freeipa/ticket/3266 Created attachment 648789 [details]
samba logs
I tried adding log level to the smb.conf.empty but, didn't seem to change it. So, I just changed it with net conf.
This is pretty much all I saw.
No, please follow my request in comment 3. The resulting log is within /var/log/httpd/error_log (i.e. IPA web server log). Ah, ok, I was looking at the wrong logs. I'll upload that shortly. Created attachment 648906 [details]
http error_log
Comment on attachment 648906 [details] http error_log Looking at the log I can see that AD DC never answers back to our attempt to connect to it with ncacn_np:win2k8r2.adlab.qe[,] connection string (SMB RPC connection, http://msdn.microsoft.com/en-us/library/cc243786%28v=prot.20%29.aspx). It most likely means that it doesn't know how to route properly traffic back to us. Compare this communication with previous one directed to our own server, starting with "Using binding ncacn_np:mgmt8.ipa2.example.com[,]". Reopening since we found cause of the issue. It is bug in Samba: https://bugzilla.samba.org/show_bug.cgi?id=9618 Re-assign to samba4. Link to external bugzilla. Can this bug be closed? Does anything need to be documented? Speaking of documentation, I think we are fine with regards to FreeIPA documentation: https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html-single/Identity_Management_Guide/index.html#hostname-requirements We already state that the hostname needs to be fully qualified. (In reply to Ann Marie Rubin from comment #24) > Can this bug be closed? Does anything need to be documented? I would prefer to keep this bug open, because it tracks a samba upstream issue which we might want to include in RHEL if fixed upstream. About documentation, maybe Nirupama would like to write a knowledge-base article about how she fixed her setup to get arround the issue? Closing; the known issue has been added to the book. |