Description of problem:
WARNING: ntpd time&date synchronization service will not be configured as
conflicting service (chronyd) is enabled
Use --force-ntpd option to disable it and force configuration of ntpd
DNS domain 'virt' is not configured for automatic KDC address lookup.
KDC address will be set to fixed value.
Discovery was successful!
DNS Domain: 1.virt
IPA Server: fedora20.1.virt
Continue to configure the system with these values? [no]: yes
Synchronizing time with KDC...
Unable to sync time with IPA NTP server, assuming the time is in sync. Please check that 123 UDP port is opened.
User authorized to enroll computers: admin
Password for admin@VIRT:
Successfully retrieved CA cert
Subject: CN=Certificate Authority,O=VIRT
Issuer: CN=Certificate Authority,O=VIRT
Valid From: Fri Jul 11 10:45:57 2014 UTC
Valid Until: Tue Jul 11 10:45:57 2034 UTC
Joining realm failed: Failed to parse result! unsupported extended operation
Failed to get keytab
child exited with 9
Installation failed. Rolling back changes.
IPA client is not configured on this system.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. run ipa-server-install on fedora20.1.virt
2. use basic simple setup with dns
3. run ipa-client-install on rawhide.1.virt
Update: this bug is currently being investigated upstream and the current plan is to release a fixed version of freeipa in the end of this week.
freeipa-4.0.2-1.fc21 has been submitted as an update for Fedora 21.
* should fix your issue,
* was pushed to the Fedora 21 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing freeipa-4.0.2-1.fc21'
as soon as you are able to.
Please go to the following url:
then log in and leave karma (feedback).
freeipa-4.0.2-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.