Red Hat Bugzilla – Bug 1126636
RHEL6.6 sssd not running after upgrade
Last modified: 2014-10-16 22:11:25 EDT
Description of problem: On IPA server running on RHEL6.5, sssd is no longer running after yum update to RHEL6.6. Version-Release number of selected component (if applicable): Orig: sssd-1.9.2-129.el6.x86_64 New: sssd-1.11.6-14.el6.x86_64 How reproducible: always Steps to Reproduce: 1. ipa-server-install on RHEL6.5 server 2. add RHEL6.6 repos to yum config 3. yum -y update 'ipa*' sssd Actual results: IPA and components are all updated but sssd is no longer running. Expected results: sssd would be running after upgrade. Additional info:
Created attachment 924029 [details] /var/log/sssd dir with debug_level = 9 after upgade.
FYI: [root@rhel6-1 ~]# ipa-server-install --setup-dns --forwarder=192.168.122.1 --hostname=$(hostname) --ip-address=$(hostname -i) -r EXAMPLE.COM -n example.com -p Secret123 -P Secret123 -a Secret123 -U The log file for this installation can be found in /var/log/ipaserver-install.log ============================================================================== This program will set up the IPA Server. This includes: * Configure a stand-alone CA (dogtag) for certificate management * Configure the Network Time Daemon (ntpd) * Create and configure an instance of Directory Server * Create and configure a Kerberos Key Distribution Center (KDC) * Configure Apache (httpd) * Configure DNS (bind) To accept the default shown in brackets, press the Enter key. Warning: skipping DNS resolution of host rhel6-1.example.com Using reverse zone 122.168.192.in-addr.arpa. The IPA Master Server will be configured with: Hostname: rhel6-1.example.com IP address: 192.168.122.61 Domain name: example.com Realm name: EXAMPLE.COM BIND DNS server will be configured to serve IPA domain with: Forwarders: 192.168.122.1 Reverse zone: 122.168.192.in-addr.arpa. Configuring NTP daemon (ntpd) [1/4]: stopping ntpd [2/4]: writing configuration [3/4]: configuring ntpd to start on boot [4/4]: starting ntpd Done configuring NTP daemon (ntpd). Configuring directory server for the CA (pkids): Estimated time 30 seconds [1/3]: creating directory server user [2/3]: creating directory server instance [3/3]: restarting directory server Done configuring directory server for the CA (pkids). Configuring certificate server (pki-cad): Estimated time 3 minutes 30 seconds [1/21]: creating certificate server user [2/21]: creating pki-ca instance [3/21]: configuring certificate server instance [4/21]: disabling nonces [5/21]: creating CA agent PKCS#12 file in /root [6/21]: creating RA agent certificate database [7/21]: importing CA chain to RA certificate database [8/21]: fixing RA database permissions [9/21]: setting up signing cert profile [10/21]: set up CRL publishing [11/21]: set certificate subject base [12/21]: enabling Subject Key Identifier [13/21]: setting audit signing renewal to 2 years [14/21]: configuring certificate server to start on boot [15/21]: restarting certificate server [16/21]: requesting RA certificate from CA [17/21]: issuing RA agent certificate [18/21]: adding RA agent as a trusted user [19/21]: configure certificate renewals [20/21]: configure Server-Cert certificate renewal [21/21]: Configure HTTP to proxy connections Done configuring certificate server (pki-cad). Configuring directory server (dirsrv): Estimated time 1 minute [1/38]: creating directory server user [2/38]: creating directory server instance [3/38]: adding default schema [4/38]: enabling memberof plugin [5/38]: enabling winsync plugin [6/38]: configuring replication version plugin [7/38]: enabling IPA enrollment plugin [8/38]: enabling ldapi [9/38]: disabling betxn plugins [10/38]: configuring uniqueness plugin [11/38]: configuring uuid plugin [12/38]: configuring modrdn plugin [13/38]: enabling entryUSN plugin [14/38]: configuring lockout plugin [15/38]: creating indices [16/38]: enabling referential integrity plugin [17/38]: configuring ssl for ds instance [18/38]: configuring certmap.conf [19/38]: configure autobind for root [20/38]: configure new location for managed entries [21/38]: restarting directory server [22/38]: adding default layout [23/38]: adding delegation layout [24/38]: adding replication acis [25/38]: creating container for managed entries [26/38]: configuring user private groups [27/38]: configuring netgroups from hostgroups [28/38]: creating default Sudo bind user [29/38]: creating default Auto Member layout [30/38]: adding range check plugin [31/38]: creating default HBAC rule allow_all [32/38]: Upload CA cert to the directory [33/38]: initializing group membership [34/38]: adding master entry [35/38]: configuring Posix uid/gid generation [36/38]: enabling compatibility plugin [37/38]: tuning directory server [38/38]: configuring directory to start on boot Done configuring directory server (dirsrv). Configuring Kerberos KDC (krb5kdc): Estimated time 30 seconds [1/10]: adding sasl mappings to the directory [2/10]: adding kerberos container to the directory [3/10]: configuring KDC [4/10]: initialize kerberos container [5/10]: adding default ACIs [6/10]: creating a keytab for the directory [7/10]: creating a keytab for the machine [8/10]: adding the password extension to the directory [9/10]: starting the KDC [10/10]: configuring KDC to start on boot Done configuring Kerberos KDC (krb5kdc). Configuring kadmin [1/2]: starting kadmin [2/2]: configuring kadmin to start on boot Done configuring kadmin. Configuring ipa_memcached [1/2]: starting ipa_memcached [2/2]: configuring ipa_memcached to start on boot Done configuring ipa_memcached. Configuring the web interface (httpd): Estimated time 1 minute [1/13]: setting mod_nss port to 443 [2/13]: setting mod_nss password file [3/13]: enabling mod_nss renegotiate [4/13]: adding URL rewriting rules [5/13]: configuring httpd [6/13]: setting up ssl [7/13]: setting up browser autoconfig [8/13]: publish CA cert [9/13]: creating a keytab for httpd [10/13]: clean up any existing httpd ccache [11/13]: configuring SELinux for httpd [12/13]: restarting httpd [13/13]: configuring httpd to start on boot Done configuring the web interface (httpd). Applying LDAP updates Restarting the directory server Restarting the KDC Configuring DNS (named) [1/9]: adding DNS container [2/9]: setting up our zone [3/9]: setting up reverse zone [4/9]: setting up our own record [5/9]: setting up kerberos principal [6/9]: setting up named.conf [7/9]: restarting named [8/9]: configuring named to start on boot [9/9]: changing resolv.conf to point to ourselves Done configuring DNS (named). Global DNS configuration in LDAP server is empty You can use 'dnsconfig-mod' command to set global DNS options that would override settings in local named.conf files Restarting the web server ============================================================================== Setup complete Next steps: 1. You must make sure these network ports are open: TCP Ports: * 80, 443: HTTP/HTTPS * 389, 636: LDAP/LDAPS * 88, 464: kerberos * 53: bind UDP Ports: * 88, 464: kerberos * 53: bind * 123: ntp 2. You can now obtain a kerberos ticket using the command: 'kinit admin' This ticket will allow you to use the IPA tools (e.g., ipa user-add) and the web user interface. Be sure to back up the CA certificate stored in /root/cacert.p12 This file is required to create replicas. The password for this file is the Directory Manager password ...removing output pointing to yum repos for rhel6.6.... [root@rhel6-1 ~]# yum -y update 'ipa*' sssd ... Installed: sssd-common.x86_64 0:1.11.6-14.el6 Dependency Installed: libbasicobjects.x86_64 0:0.1.1-11.el6 python-sssdconfig.noarch 0:1.11.6-14.el6 sssd-ad.x86_64 0:1.11.6-14.el6 sssd-common-pac.x86_64 0:1.11.6-14.el6 sssd-ipa.x86_64 0:1.11.6-14.el6 sssd-krb5.x86_64 0:1.11.6-14.el6 sssd-krb5-common.x86_64 0:1.11.6-14.el6 sssd-ldap.x86_64 0:1.11.6-14.el6 sssd-proxy.x86_64 0:1.11.6-14.el6 Updated: ipa-admintools.x86_64 0:3.0.0-42.el6 ipa-client.x86_64 0:3.0.0-42.el6 ipa-python.x86_64 0:3.0.0-42.el6 ipa-server.x86_64 0:3.0.0-42.el6 ipa-server-selinux.x86_64 0:3.0.0-42.el6 sssd.x86_64 0:1.11.6-14.el6 Dependency Updated: 389-ds-base.x86_64 0:1.2.11.15-38.el6 389-ds-base-libs.x86_64 0:1.2.11.15-38.el6 libcollection.x86_64 0:0.6.2-11.el6 libdhash.x86_64 0:0.4.3-11.el6 libini_config.x86_64 0:1.1.0-11.el6 libipa_hbac.x86_64 0:1.11.6-14.el6 libipa_hbac-python.x86_64 0:1.11.6-14.el6 libpath_utils.x86_64 0:0.2.1-11.el6 libref_array.x86_64 0:0.1.4-11.el6 libsss_idmap.x86_64 0:1.11.6-14.el6 sssd-client.x86_64 0:1.11.6-14.el6 Replaced: libsss_autofs.x86_64 0:1.9.2-129.el6 Complete! [root@rhel6-1 ~]# ps -ef|grep sssd root 6102 1264 0 17:57 pts/0 00:00:00 grep sssd
This part is interesting: (Mon Aug 4 17:52:16 2014) [sssd[be[example.com]]] [load_backend_module] (0x0010): Unable to load ipa module with path (/usr/lib64/sssd/libsss_ipa.so), error: /usr/lib64/sssd/libsss_ipa.so: undefined symbol: resolv_get_family_order resolv_get_family_order is a function that was removed during 1.10 development. I suspect that /usr/lib64/sssd/libsss_ipa.so is a stray IPA provider from 6.5. What does "rpm -qf /usr/lib64/sssd/libsss_ipa.so" say after the upgrade? Does your system has the sssd-ipa package installed after the upgrade? Does sssd restart manually after the whole yum transaction has been completed?
Jakub, [root@rhel6-1 ~]# rpm -qf /usr/lib64/sssd/libsss_ipa.so sssd-ipa-1.11.6-14.el6.x86_64 Yes, it does restart after the upgrade: [root@rhel6-1 ~]# ps -ef|grep sssd root 16382 16369 0 22:12 pts/0 00:00:00 grep sssd [root@rhel6-1 ~]# service sssd restart Stopping sssd: cat: /var/run/sssd.pid: No such file or directory [FAILED] Starting sssd: [ OK ]
Thanks! In that case I suspect we're looking at an ordering issue where we attempt to restart sssd before all its components are updated. Maybe you uncovered the bug because you used "ipa sssd" in your filter, so sssd-ipa and sssd-common might have been updated at different times. If you can reproduce the bug easily (maybe using some 6.5 snapshot), can you try this build, perhaps with yum localinstall or similar? https://brewweb.devel.redhat.com/taskinfo?taskID=7791703 The difference is that with this build, the restart is done on %posttrans, not on %post, which means after the whole upgrade transaction finished. The alternative would be to make the Requires stricter, I'm not sure which is better yet... thanks again for reporting the issue.
Jakub, Thanks for getting back to me so quick on this. It looks like that didn't fix the issue though. From /var/log/yum.log: Aug 05 15:58:26 Updated: libdhash-0.4.3-11.el6.x86_64 Aug 05 15:58:27 Updated: libsss_idmap-1.11.6-14.el6.x86_64 Aug 05 15:58:28 Installed: libbasicobjects-0.1.1-11.el6.x86_64 Aug 05 15:58:29 Updated: libcollection-0.6.2-11.el6.x86_64 Aug 05 15:58:30 Updated: libref_array-0.1.4-11.el6.x86_64 Aug 05 15:58:32 Updated: libipa_hbac-1.11.6-14.el6.x86_64 Aug 05 15:58:32 Updated: libipa_hbac-python-1.11.6-14.el6.x86_64 Aug 05 15:58:36 Updated: ipa-python-3.0.0-42.el6.x86_64 Aug 05 15:58:37 Updated: sssd-client-1.11.6-14.el6.x86_64 Aug 05 15:58:38 Updated: 389-ds-base-libs-1.2.11.15-38.el6.x86_64 Aug 05 15:59:08 Updated: 389-ds-base-1.2.11.15-38.el6.x86_64 Aug 05 15:59:09 Installed: python-sssdconfig-1.11.6-14.el6.noarch Aug 05 15:59:10 Updated: libpath_utils-0.2.1-11.el6.x86_64 Aug 05 15:59:11 Updated: libini_config-1.1.0-11.el6.x86_64 Aug 05 15:59:19 Installed: sssd-common-1.11.6-14.el6.x86_64 Aug 05 15:59:20 Installed: sssd-krb5-common-1.11.6-14.el6.x86_64 Aug 05 15:59:22 Installed: sssd-common-pac-1.11.6-14.el6.x86_64 Aug 05 15:59:24 Installed: sssd-ipa-1.11.6-14.el6.x86_64 Aug 05 15:59:25 Installed: sssd-ad-1.11.6-14.el6.x86_64 Aug 05 15:59:26 Installed: sssd-krb5-1.11.6-14.el6.x86_64 Aug 05 15:59:27 Installed: sssd-ldap-1.11.6-14.el6.x86_64 Aug 05 15:59:28 Installed: sssd-proxy-1.11.6-14.el6.x86_64 Aug 05 15:59:29 Updated: sssd-1.11.6-14.el6.x86_64 Aug 05 15:59:30 Updated: ipa-client-3.0.0-42.el6.x86_64 Aug 05 15:59:31 Updated: ipa-admintools-3.0.0-42.el6.x86_64 Aug 05 16:00:10 Updated: ipa-server-3.0.0-42.el6.x86_64 Aug 05 16:00:37 Updated: ipa-server-selinux-3.0.0-42.el6.x86_64 Aug 05 16:02:07 Erased: libsss_autofs ... [root@rhel6-4 yum.local.d]# ps -ef|grep sssd root 7643 1269 0 16:07 pts/0 00:00:00 grep sssd I see this in the sssd log again too: (Tue Aug 5 15:59:19 2014) [sssd[be[testrelm.test]]] [load_backend_module] (0x0010): Unable to load ipa module with path (/usr/lib64/sssd/libsss_ipa.so), error: /usr/lib64/sssd/libsss_ipa.so: undefined symbol: resolv_get_family_order (Tue Aug 5 15:59:19 2014) [sssd[be[testrelm.test]]] [be_process_init] (0x0010): fatal error initializing data providers (Tue Aug 5 15:59:19 2014) [sssd[be[testrelm.test]]] [main] (0x0010): Could not initialize backend [79] [root@rhel6-4 yum.local.d]# So, is this the ordering problem you thought? because sssd-common is before sssd-ipa? Thanks, Scott
Yes, I think the root cause is sssd-common being updated before sssd-ipa. I need to reproduce locally, I guess..
I could reproduce on a local VM. Cloning upstream.
Upstream ticket: https://fedorahosted.org/sssd/ticket/2399
Scott, can you try using this test repository? --------------- # cat /etc/yum.repos.d/bz.repo [bz1126636] name=test packages for bz1126636 baseurl=https://jhrozek.fedorapeople.org/bz1126636/ enabled=1 gpgcheck=0 skip_if_unavailable=True --------------- Please check if the packages are being pulled from the right repository during testing. Using these packages, I got consistent successful upgrade on a machine that was failing on upgrade consistently.
That does seem to look better: Installed: sssd-common.x86_64 0:1.11.6-14.test.el6 Dependency Installed: libbasicobjects.x86_64 0:0.1.1-11.el6 python-sssdconfig.noarch 0:1.11.6-14.test.el6 sssd-ad.x86_64 0:1.11.6-14.test.el6 sssd-common-pac.x86_64 0:1.11.6-14.test.el6 sssd-ipa.x86_64 0:1.11.6-14.test.el6 sssd-krb5.x86_64 0:1.11.6-14.test.el6 sssd-krb5-common.x86_64 0:1.11.6-14.test.el6 sssd-ldap.x86_64 0:1.11.6-14.test.el6 sssd-proxy.x86_64 0:1.11.6-14.test.el6 Updated: ipa-admintools.x86_64 0:3.0.0-42.el6 ipa-client.x86_64 0:3.0.0-42.el6 ipa-python.x86_64 0:3.0.0-42.el6 ipa-server.x86_64 0:3.0.0-42.el6 ipa-server-selinux.x86_64 0:3.0.0-42.el6 sssd.x86_64 0:1.11.6-14.test.el6 Dependency Updated: 389-ds-base.x86_64 0:1.2.11.15-39.el6 389-ds-base-libs.x86_64 0:1.2.11.15-39.el6 libcollection.x86_64 0:0.6.2-11.el6 libdhash.x86_64 0:0.4.3-11.el6 libini_config.x86_64 0:1.1.0-11.el6 libipa_hbac.x86_64 0:1.11.6-14.test.el6 libipa_hbac-python.x86_64 0:1.11.6-14.test.el6 libpath_utils.x86_64 0:0.2.1-11.el6 libref_array.x86_64 0:0.1.4-11.el6 libsss_idmap.x86_64 0:1.11.6-14.test.el6 sssd-client.x86_64 0:1.11.6-14.test.el6 Replaced: libsss_autofs.x86_64 0:1.9.2-129.el6 Complete! [root@rhel6-1 ~]# ps -ef|grep sssd root 4721 1 0 11:57 ? 00:00:00 /usr/sbin/sssd -f -D root 4722 4721 0 11:57 ? 00:00:00 /usr/libexec/sssd/sssd_be --domain example.com --debug-to-files root 4723 4721 0 11:57 ? 00:00:00 /usr/libexec/sssd/sssd_nss --debug-to-files root 4724 4721 0 11:57 ? 00:00:00 /usr/libexec/sssd/sssd_pam --debug-to-files root 4725 4721 0 11:57 ? 00:00:00 /usr/libexec/sssd/sssd_ssh --debug-to-files root 4726 4721 0 11:57 ? 00:00:00 /usr/libexec/sssd/sssd_pac --debug-to-files root 4794 1260 0 11:58 pts/0 00:00:00 grep sssd
Thank you for testing, I will send the patch upstream.
Fixed upstream: master: 192027debeaa991690160c3cb68480fe54ad8fdf sssd-1-11: 34e1d900fcb37a8e9f8b9c28467f37cd30ed854a
Verified. Version: sssd-1.11.6-20.el6.x86_64 Results: [root@rhel6-1 ~]# yum update -y 'ipa*' sssd openldap Loaded plugins: product-id, subscription-manager This system is not registered to Red Hat Subscription Management. You can use subscription-manager to register. beaker-client | 1.5 kB 00:00 beaker-client/primary | 13 kB 00:00 beaker-client 55/55 beaker-rhel-6.6-latest-optional | 3.8 kB 00:00 beaker-rhel-6.6-latest-optional/primary_db | 1.2 MB 00:03 beaker-rhel-6.6-latest-server | 4.1 kB 00:00 beaker-rhel-6.6-latest-server/primary_db | 3.1 MB 00:20 beaker-rhel65-optional | 3.7 kB 00:00 beaker-rhel65-server | 3.9 kB 00:00 spoore-r6 | 1.3 kB 00:00 spoore-r6/primary | 7.9 kB 00:00 spoore-r6 27/27 Setting up Update Process Resolving Dependencies --> Running transaction check ---> Package ipa-admintools.x86_64 0:3.0.0-37.el6 will be updated ---> Package ipa-admintools.x86_64 0:3.0.0-42.el6 will be an update ---> Package ipa-client.x86_64 0:3.0.0-37.el6 will be updated ---> Package ipa-client.x86_64 0:3.0.0-42.el6 will be an update ---> Package ipa-python.x86_64 0:3.0.0-37.el6 will be updated ---> Package ipa-python.x86_64 0:3.0.0-42.el6 will be an update ---> Package ipa-server.x86_64 0:3.0.0-37.el6 will be updated ---> Package ipa-server.x86_64 0:3.0.0-42.el6 will be an update --> Processing Dependency: 389-ds-base >= 1.2.11.15-38 for package: ipa-server-3.0.0-42.el6.x86_64 ---> Package ipa-server-selinux.x86_64 0:3.0.0-37.el6 will be updated ---> Package ipa-server-selinux.x86_64 0:3.0.0-42.el6 will be an update ---> Package openldap.x86_64 0:2.4.23-32.el6_4.1 will be updated --> Processing Dependency: openldap = 2.4.23-32.el6_4.1 for package: openldap-clients-2.4.23-32.el6_4.1.x86_64 ---> Package openldap.x86_64 0:2.4.39-8.el6 will be an update ---> Package sssd.x86_64 0:1.9.2-129.el6 will be updated ---> Package sssd.x86_64 0:1.11.6-20.el6 will be an update --> Processing Dependency: python-sssdconfig = 1.11.6-20.el6 for package: sssd-1.11.6-20.el6.x86_64 --> Processing Dependency: sssd-ad = 1.11.6-20.el6 for package: sssd-1.11.6-20.el6.x86_64 --> Processing Dependency: sssd-common = 1.11.6-20.el6 for package: sssd-1.11.6-20.el6.x86_64 --> Processing Dependency: sssd-common-pac = 1.11.6-20.el6 for package: sssd-1.11.6-20.el6.x86_64 --> Processing Dependency: sssd-ipa = 1.11.6-20.el6 for package: sssd-1.11.6-20.el6.x86_64 --> Processing Dependency: sssd-krb5 = 1.11.6-20.el6 for package: sssd-1.11.6-20.el6.x86_64 --> Processing Dependency: sssd-ldap = 1.11.6-20.el6 for package: sssd-1.11.6-20.el6.x86_64 --> Processing Dependency: sssd-proxy = 1.11.6-20.el6 for package: sssd-1.11.6-20.el6.x86_64 --> Running transaction check ---> Package 389-ds-base.x86_64 0:1.2.11.15-29.el6 will be updated ---> Package 389-ds-base.x86_64 0:1.2.11.15-39.el6 will be an update --> Processing Dependency: 389-ds-base-libs = 1.2.11.15-39.el6 for package: 389-ds-base-1.2.11.15-39.el6.x86_64 ---> Package libsss_autofs.x86_64 0:1.9.2-129.el6 will be obsoleted ---> Package openldap-clients.x86_64 0:2.4.23-32.el6_4.1 will be updated ---> Package openldap-clients.x86_64 0:2.4.39-8.el6 will be an update ---> Package python-sssdconfig.noarch 0:1.11.6-20.el6 will be installed ---> Package sssd-ad.x86_64 0:1.11.6-20.el6 will be installed --> Processing Dependency: sssd-krb5-common = 1.11.6-20.el6 for package: sssd-ad-1.11.6-20.el6.x86_64 --> Processing Dependency: libdhash.so.1(DHASH_0.4.3)(64bit) for package: sssd-ad-1.11.6-20.el6.x86_64 --> Processing Dependency: libsss_krb5_common.so()(64bit) for package: sssd-ad-1.11.6-20.el6.x86_64 ---> Package sssd-common.x86_64 0:1.11.6-20.el6 will be obsoleting --> Processing Dependency: libsss_idmap(x86-64) = 1.11.6-20.el6 for package: sssd-common-1.11.6-20.el6.x86_64 --> Processing Dependency: sssd-client(x86-64) = 1.11.6-20.el6 for package: sssd-common-1.11.6-20.el6.x86_64 --> Processing Dependency: libini_config.so.5(INI_CONFIG_1.1.0)(64bit) for package: sssd-common-1.11.6-20.el6.x86_64 --> Processing Dependency: libbasicobjects.so.0()(64bit) for package: sssd-common-1.11.6-20.el6.x86_64 --> Processing Dependency: libcollection.so.4()(64bit) for package: sssd-common-1.11.6-20.el6.x86_64 --> Processing Dependency: libini_config.so.5()(64bit) for package: sssd-common-1.11.6-20.el6.x86_64 ---> Package sssd-common-pac.x86_64 0:1.11.6-20.el6 will be installed ---> Package sssd-ipa.x86_64 0:1.11.6-20.el6 will be installed --> Processing Dependency: libipa_hbac(x86-64) = 1.11.6-20.el6 for package: sssd-ipa-1.11.6-20.el6.x86_64 ---> Package sssd-krb5.x86_64 0:1.11.6-20.el6 will be installed ---> Package sssd-ldap.x86_64 0:1.11.6-20.el6 will be installed ---> Package sssd-proxy.x86_64 0:1.11.6-20.el6 will be installed --> Running transaction check ---> Package 389-ds-base-libs.x86_64 0:1.2.11.15-29.el6 will be updated ---> Package 389-ds-base-libs.x86_64 0:1.2.11.15-39.el6 will be an update ---> Package libbasicobjects.x86_64 0:0.1.1-11.el6 will be installed ---> Package libcollection.x86_64 0:0.6.0-9.el6 will be updated ---> Package libcollection.x86_64 0:0.6.2-11.el6 will be an update ---> Package libdhash.x86_64 0:0.4.2-9.el6 will be updated ---> Package libdhash.x86_64 0:0.4.3-11.el6 will be an update ---> Package libini_config.x86_64 0:0.6.1-9.el6 will be updated ---> Package libini_config.x86_64 0:1.1.0-11.el6 will be an update --> Processing Dependency: libpath_utils = 0.2.1-11.el6 for package: libini_config-1.1.0-11.el6.x86_64 --> Processing Dependency: libref_array = 0.1.4-11.el6 for package: libini_config-1.1.0-11.el6.x86_64 --> Processing Dependency: libpath_utils.so.1(PATH_UTILS_0.2.1)(64bit) for package: libini_config-1.1.0-11.el6.x86_64 --> Processing Dependency: libref_array.so.1(REF_ARRAY_0.1.1)(64bit) for package: libini_config-1.1.0-11.el6.x86_64 --> Processing Dependency: libref_array.so.1(REF_ARRAY_0.1.4)(64bit) for package: libini_config-1.1.0-11.el6.x86_64 ---> Package libipa_hbac.x86_64 0:1.9.2-129.el6 will be updated --> Processing Dependency: libipa_hbac = 1.9.2-129.el6 for package: libipa_hbac-python-1.9.2-129.el6.x86_64 ---> Package libipa_hbac.x86_64 0:1.11.6-20.el6 will be an update ---> Package libsss_idmap.x86_64 0:1.9.2-129.el6 will be updated ---> Package libsss_idmap.x86_64 0:1.11.6-20.el6 will be an update ---> Package sssd-client.x86_64 0:1.9.2-129.el6 will be updated ---> Package sssd-client.x86_64 0:1.11.6-20.el6 will be an update ---> Package sssd-krb5-common.x86_64 0:1.11.6-20.el6 will be installed --> Running transaction check ---> Package libipa_hbac-python.x86_64 0:1.9.2-129.el6 will be updated ---> Package libipa_hbac-python.x86_64 0:1.11.6-20.el6 will be an update ---> Package libpath_utils.x86_64 0:0.2.1-9.el6 will be updated ---> Package libpath_utils.x86_64 0:0.2.1-11.el6 will be an update ---> Package libref_array.x86_64 0:0.1.1-9.el6 will be updated ---> Package libref_array.x86_64 0:0.1.4-11.el6 will be an update --> Finished Dependency Resolution Dependencies Resolved ======================================================================================================= Package Arch Version Repository Size ======================================================================================================= Installing: sssd-common x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 825 k replacing libsss_autofs.x86_64 1.9.2-129.el6 Updating: ipa-admintools x86_64 3.0.0-42.el6 beaker-rhel-6.6-latest-server 67 k ipa-client x86_64 3.0.0-42.el6 beaker-rhel-6.6-latest-server 145 k ipa-python x86_64 3.0.0-42.el6 beaker-rhel-6.6-latest-server 928 k ipa-server x86_64 3.0.0-42.el6 beaker-rhel-6.6-latest-server 1.1 M ipa-server-selinux x86_64 3.0.0-42.el6 beaker-rhel-6.6-latest-server 66 k openldap x86_64 2.4.39-8.el6 beaker-rhel-6.6-latest-server 280 k sssd x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 86 k Installing for dependencies: libbasicobjects x86_64 0.1.1-11.el6 beaker-rhel-6.6-latest-server 21 k python-sssdconfig noarch 1.11.6-20.el6 beaker-rhel-6.6-latest-server 117 k sssd-ad x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 139 k sssd-common-pac x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 118 k sssd-ipa x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 192 k sssd-krb5 x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 107 k sssd-krb5-common x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 157 k sssd-ldap x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 164 k sssd-proxy x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 113 k Updating for dependencies: 389-ds-base x86_64 1.2.11.15-39.el6 beaker-rhel-6.6-latest-server 1.5 M 389-ds-base-libs x86_64 1.2.11.15-39.el6 beaker-rhel-6.6-latest-server 416 k libcollection x86_64 0.6.2-11.el6 beaker-rhel-6.6-latest-server 36 k libdhash x86_64 0.4.3-11.el6 beaker-rhel-6.6-latest-server 24 k libini_config x86_64 1.1.0-11.el6 beaker-rhel-6.6-latest-server 46 k libipa_hbac x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 91 k libipa_hbac-python x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 85 k libpath_utils x86_64 0.2.1-11.el6 beaker-rhel-6.6-latest-server 24 k libref_array x86_64 0.1.4-11.el6 beaker-rhel-6.6-latest-server 23 k libsss_idmap x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 95 k openldap-clients x86_64 2.4.39-8.el6 beaker-rhel-6.6-latest-server 162 k sssd-client x86_64 1.11.6-20.el6 beaker-rhel-6.6-latest-server 125 k Transaction Summary ======================================================================================================= Install 10 Package(s) Upgrade 19 Package(s) Total download size: 7.1 M Downloading Packages: (1/29): 389-ds-base-1.2.11.15-39.el6.x86_64.rpm | 1.5 MB 00:14 (2/29): 389-ds-base-libs-1.2.11.15-39.el6.x86_64.rpm | 416 kB 00:01 (3/29): ipa-admintools-3.0.0-42.el6.x86_64.rpm | 67 kB 00:00 (4/29): ipa-client-3.0.0-42.el6.x86_64.rpm | 145 kB 00:00 (5/29): ipa-python-3.0.0-42.el6.x86_64.rpm | 928 kB 00:04 (6/29): ipa-server-3.0.0-42.el6.x86_64.rpm | 1.1 MB 00:04 (7/29): ipa-server-selinux-3.0.0-42.el6.x86_64.rpm | 66 kB 00:00 (8/29): libbasicobjects-0.1.1-11.el6.x86_64.rpm | 21 kB 00:00 (9/29): libcollection-0.6.2-11.el6.x86_64.rpm | 36 kB 00:00 (10/29): libdhash-0.4.3-11.el6.x86_64.rpm | 24 kB 00:00 (11/29): libini_config-1.1.0-11.el6.x86_64.rpm | 46 kB 00:00 (12/29): libipa_hbac-1.11.6-20.el6.x86_64.rpm | 91 kB 00:00 (13/29): libipa_hbac-python-1.11.6-20.el6.x86_64.rpm | 85 kB 00:00 (14/29): libpath_utils-0.2.1-11.el6.x86_64.rpm | 24 kB 00:00 (15/29): libref_array-0.1.4-11.el6.x86_64.rpm | 23 kB 00:00 (16/29): libsss_idmap-1.11.6-20.el6.x86_64.rpm | 95 kB 00:00 (17/29): openldap-2.4.39-8.el6.x86_64.rpm | 280 kB 00:00 (18/29): openldap-clients-2.4.39-8.el6.x86_64.rpm | 162 kB 00:00 (19/29): python-sssdconfig-1.11.6-20.el6.noarch.rpm | 117 kB 00:00 (20/29): sssd-1.11.6-20.el6.x86_64.rpm | 86 kB 00:00 (21/29): sssd-ad-1.11.6-20.el6.x86_64.rpm | 139 kB 00:00 (22/29): sssd-client-1.11.6-20.el6.x86_64.rpm | 125 kB 00:00 (23/29): sssd-common-1.11.6-20.el6.x86_64.rpm | 825 kB 00:00 (24/29): sssd-common-pac-1.11.6-20.el6.x86_64.rpm | 118 kB 00:00 (25/29): sssd-ipa-1.11.6-20.el6.x86_64.rpm | 192 kB 00:00 (26/29): sssd-krb5-1.11.6-20.el6.x86_64.rpm | 107 kB 00:00 (27/29): sssd-krb5-common-1.11.6-20.el6.x86_64.rpm | 157 kB 00:00 (28/29): sssd-ldap-1.11.6-20.el6.x86_64.rpm | 164 kB 00:00 (29/29): sssd-proxy-1.11.6-20.el6.x86_64.rpm | 113 kB 00:00 ------------------------------------------------------------------------------------------------------- Total 208 kB/s | 7.1 MB 00:35 Running rpm_check_debug Running Transaction Test Transaction Test Succeeded Running Transaction Updating : openldap-2.4.39-8.el6.x86_64 1/49 Updating : libdhash-0.4.3-11.el6.x86_64 2/49 Updating : libsss_idmap-1.11.6-20.el6.x86_64 3/49 Installing : libbasicobjects-0.1.1-11.el6.x86_64 4/49 Updating : libcollection-0.6.2-11.el6.x86_64 5/49 Updating : libref_array-0.1.4-11.el6.x86_64 6/49 Updating : openldap-clients-2.4.39-8.el6.x86_64 7/49 Updating : libipa_hbac-1.11.6-20.el6.x86_64 8/49 Updating : libipa_hbac-python-1.11.6-20.el6.x86_64 9/49 Updating : ipa-python-3.0.0-42.el6.x86_64 10/49 Updating : 389-ds-base-libs-1.2.11.15-39.el6.x86_64 11/49 Updating : 389-ds-base-1.2.11.15-39.el6.x86_64 12/49 Installing : python-sssdconfig-1.11.6-20.el6.noarch 13/49 Updating : libpath_utils-0.2.1-11.el6.x86_64 14/49 Updating : libini_config-1.1.0-11.el6.x86_64 15/49 Updating : sssd-client-1.11.6-20.el6.x86_64 16/49 Installing : sssd-common-1.11.6-20.el6.x86_64 17/49 Installing : sssd-krb5-common-1.11.6-20.el6.x86_64 18/49 Installing : sssd-common-pac-1.11.6-20.el6.x86_64 19/49 Installing : sssd-ipa-1.11.6-20.el6.x86_64 20/49 Installing : sssd-ad-1.11.6-20.el6.x86_64 21/49 Installing : sssd-ldap-1.11.6-20.el6.x86_64 22/49 Installing : sssd-krb5-1.11.6-20.el6.x86_64 23/49 Installing : sssd-proxy-1.11.6-20.el6.x86_64 24/49 Updating : sssd-1.11.6-20.el6.x86_64 25/49 Updating : ipa-client-3.0.0-42.el6.x86_64 26/49 Updating : ipa-admintools-3.0.0-42.el6.x86_64 27/49 Updating : ipa-server-3.0.0-42.el6.x86_64 28/49 Updating : ipa-server-selinux-3.0.0-42.el6.x86_64 29/49 Cleanup : ipa-server-selinux-3.0.0-37.el6.x86_64 30/49 Cleanup : ipa-server-3.0.0-37.el6.x86_64 31/49 Cleanup : 389-ds-base-1.2.11.15-29.el6.x86_64 32/49 Cleanup : ipa-admintools-3.0.0-37.el6.x86_64 33/49 Cleanup : ipa-client-3.0.0-37.el6.x86_64 34/49 Cleanup : sssd-1.9.2-129.el6.x86_64 35/49 Cleanup : ipa-python-3.0.0-37.el6.x86_64 36/49 Cleanup : libini_config-0.6.1-9.el6.x86_64 37/49 Cleanup : libipa_hbac-python-1.9.2-129.el6.x86_64 38/49 Cleanup : 389-ds-base-libs-1.2.11.15-29.el6.x86_64 39/49 Cleanup : openldap-clients-2.4.23-32.el6_4.1.x86_64 40/49 Cleanup : openldap-2.4.23-32.el6_4.1.x86_64 41/49 Cleanup : libipa_hbac-1.9.2-129.el6.x86_64 42/49 Cleanup : libcollection-0.6.0-9.el6.x86_64 43/49 Cleanup : libpath_utils-0.2.1-9.el6.x86_64 44/49 Cleanup : libref_array-0.1.1-9.el6.x86_64 45/49 Cleanup : libdhash-0.4.2-9.el6.x86_64 46/49 Cleanup : libsss_idmap-1.9.2-129.el6.x86_64 47/49 Cleanup : sssd-client-1.9.2-129.el6.x86_64 48/49 Erasing : libsss_autofs-1.9.2-129.el6.x86_64 49/49 beaker-rhel-6.6-latest-server/productid | 1.6 kB 00:00 Verifying : sssd-client-1.11.6-20.el6.x86_64 1/49 Verifying : libref_array-0.1.4-11.el6.x86_64 2/49 Verifying : ipa-server-selinux-3.0.0-42.el6.x86_64 3/49 Verifying : libsss_idmap-1.11.6-20.el6.x86_64 4/49 Verifying : ipa-server-3.0.0-42.el6.x86_64 5/49 Verifying : libipa_hbac-1.11.6-20.el6.x86_64 6/49 Verifying : openldap-2.4.39-8.el6.x86_64 7/49 Verifying : libdhash-0.4.3-11.el6.x86_64 8/49 Verifying : sssd-krb5-common-1.11.6-20.el6.x86_64 9/49 Verifying : libipa_hbac-python-1.11.6-20.el6.x86_64 10/49 Verifying : libcollection-0.6.2-11.el6.x86_64 11/49 Verifying : libpath_utils-0.2.1-11.el6.x86_64 12/49 Verifying : sssd-1.11.6-20.el6.x86_64 13/49 Verifying : openldap-clients-2.4.39-8.el6.x86_64 14/49 Verifying : ipa-python-3.0.0-42.el6.x86_64 15/49 Verifying : sssd-common-pac-1.11.6-20.el6.x86_64 16/49 Verifying : sssd-ipa-1.11.6-20.el6.x86_64 17/49 Verifying : python-sssdconfig-1.11.6-20.el6.noarch 18/49 Verifying : sssd-ldap-1.11.6-20.el6.x86_64 19/49 Verifying : 389-ds-base-1.2.11.15-39.el6.x86_64 20/49 Verifying : libbasicobjects-0.1.1-11.el6.x86_64 21/49 Verifying : libini_config-1.1.0-11.el6.x86_64 22/49 Verifying : sssd-ad-1.11.6-20.el6.x86_64 23/49 Verifying : ipa-admintools-3.0.0-42.el6.x86_64 24/49 Verifying : sssd-proxy-1.11.6-20.el6.x86_64 25/49 Verifying : sssd-krb5-1.11.6-20.el6.x86_64 26/49 Verifying : 389-ds-base-libs-1.2.11.15-39.el6.x86_64 27/49 Verifying : sssd-common-1.11.6-20.el6.x86_64 28/49 Verifying : ipa-client-3.0.0-42.el6.x86_64 29/49 Verifying : openldap-clients-2.4.23-32.el6_4.1.x86_64 30/49 Verifying : ipa-admintools-3.0.0-37.el6.x86_64 31/49 Verifying : openldap-2.4.23-32.el6_4.1.x86_64 32/49 Verifying : sssd-1.9.2-129.el6.x86_64 33/49 Verifying : sssd-client-1.9.2-129.el6.x86_64 34/49 Verifying : ipa-client-3.0.0-37.el6.x86_64 35/49 Verifying : libsss_idmap-1.9.2-129.el6.x86_64 36/49 Verifying : libipa_hbac-1.9.2-129.el6.x86_64 37/49 Verifying : ipa-server-selinux-3.0.0-37.el6.x86_64 38/49 Verifying : libipa_hbac-python-1.9.2-129.el6.x86_64 39/49 Verifying : ipa-server-3.0.0-37.el6.x86_64 40/49 Verifying : 389-ds-base-libs-1.2.11.15-29.el6.x86_64 41/49 Verifying : libini_config-0.6.1-9.el6.x86_64 42/49 Verifying : libdhash-0.4.2-9.el6.x86_64 43/49 Verifying : ipa-python-3.0.0-37.el6.x86_64 44/49 Verifying : libcollection-0.6.0-9.el6.x86_64 45/49 Verifying : 389-ds-base-1.2.11.15-29.el6.x86_64 46/49 Verifying : libref_array-0.1.1-9.el6.x86_64 47/49 Verifying : libsss_autofs-1.9.2-129.el6.x86_64 48/49 Verifying : libpath_utils-0.2.1-9.el6.x86_64 49/49 Installed: sssd-common.x86_64 0:1.11.6-20.el6 Dependency Installed: libbasicobjects.x86_64 0:0.1.1-11.el6 python-sssdconfig.noarch 0:1.11.6-20.el6 sssd-ad.x86_64 0:1.11.6-20.el6 sssd-common-pac.x86_64 0:1.11.6-20.el6 sssd-ipa.x86_64 0:1.11.6-20.el6 sssd-krb5.x86_64 0:1.11.6-20.el6 sssd-krb5-common.x86_64 0:1.11.6-20.el6 sssd-ldap.x86_64 0:1.11.6-20.el6 sssd-proxy.x86_64 0:1.11.6-20.el6 Updated: ipa-admintools.x86_64 0:3.0.0-42.el6 ipa-client.x86_64 0:3.0.0-42.el6 ipa-python.x86_64 0:3.0.0-42.el6 ipa-server.x86_64 0:3.0.0-42.el6 ipa-server-selinux.x86_64 0:3.0.0-42.el6 openldap.x86_64 0:2.4.39-8.el6 sssd.x86_64 0:1.11.6-20.el6 Dependency Updated: 389-ds-base.x86_64 0:1.2.11.15-39.el6 389-ds-base-libs.x86_64 0:1.2.11.15-39.el6 libcollection.x86_64 0:0.6.2-11.el6 libdhash.x86_64 0:0.4.3-11.el6 libini_config.x86_64 0:1.1.0-11.el6 libipa_hbac.x86_64 0:1.11.6-20.el6 libipa_hbac-python.x86_64 0:1.11.6-20.el6 libpath_utils.x86_64 0:0.2.1-11.el6 libref_array.x86_64 0:0.1.4-11.el6 libsss_idmap.x86_64 0:1.11.6-20.el6 openldap-clients.x86_64 0:2.4.39-8.el6 sssd-client.x86_64 0:1.11.6-20.el6 Replaced: libsss_autofs.x86_64 0:1.9.2-129.el6 Complete! [root@rhel6-1 ~]# ipactl status Directory Service: RUNNING KDC Service: RUNNING KPASSWD Service: RUNNING DNS Service: RUNNING MEMCACHE Service: RUNNING HTTP Service: RUNNING CA Service: RUNNING [root@rhel6-1 ~]# rpm -q sssd sssd-1.11.6-20.el6.x86_64 [root@rhel6-1 ~]# ps -ef|grep sssd root 15552 1 0 09:12 ? 00:00:00 /usr/sbin/sssd -f -D root 15553 15552 0 09:12 ? 00:00:00 /usr/libexec/sssd/sssd_be --domain example.com --debug-to-files root 15554 15552 0 09:12 ? 00:00:00 /usr/libexec/sssd/sssd_nss --debug-to-files root 15555 15552 0 09:12 ? 00:00:00 /usr/libexec/sssd/sssd_pam --debug-to-files root 15556 15552 0 09:12 ? 00:00:00 /usr/libexec/sssd/sssd_ssh --debug-to-files root 15557 15552 0 09:12 ? 00:00:00 /usr/libexec/sssd/sssd_pac --debug-to-files root 16108 1276 0 09:41 pts/0 00:00:00 grep sssd
Thank you very much for catching this issue. This was a nasty one.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2014-1375.html