Bug 1128420 - adding cifs Kerberos principal: Operation failed! PrincipalName not found.
Summary: adding cifs Kerberos principal: Operation failed! PrincipalName not found.
Alias: None
Product: Fedora
Classification: Fedora
Component: freeipa
Version: 20
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
Assignee: Rob Crittenden
QA Contact: Fedora Extras Quality Assurance
Depends On:
TreeView+ depends on / blocked
Reported: 2014-08-10 11:26 UTC by William Brown
Modified: 2014-08-10 11:34 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2014-08-10 11:34:38 UTC

Attachments (Terms of Use)
Log of adtrust installation attempt (34.32 KB, text/x-c)
2014-08-10 11:26 UTC, William Brown
no flags Details

Description William Brown 2014-08-10 11:26:20 UTC
Created attachment 925498 [details]
Log of adtrust installation attempt

Description of problem:
From a fresh install of FreeIPA, ADTrust installation fails. The key part is:

  [5/20]: adding cifs Kerberos principal
ipa.ipalib.plugins.service.service_add: DEBUG    raw: service_add(u'cifs/lorna.dev.blackhats.net.au@DEV.BLACKHATS.NET.AU')
ipa.ipalib.plugins.service.service_add: DEBUG    service_add(u'cifs/lorna.dev.blackhats.net.au@DEV.BLACKHATS.NET.AU', force=False, all=False, raw=False, no_members=False)
ipa.ipalib.plugins.host.host_show: DEBUG    raw: host_show(u'lorna.dev.blackhats.net.au')
ipa.ipalib.plugins.host.host_show: DEBUG    host_show(u'lorna.dev.blackhats.net.au', rights=False, all=False, raw=False, no_members=False)
ipa.ipalib.plugins.service.service_add: DEBUG    IPA: DNS A record lookup failed for lorna.dev.blackhats.net.au
ipa         : DEBUG    Starting external process
ipa         : DEBUG    args=ipa-getkeytab --server lorna.dev.blackhats.net.au --principal cifs/lorna.dev.blackhats.net.au@DEV.BLACKHATS.NET.AU -k /etc/samba/samba.keytab
ipa         : DEBUG    Process finished, return code=9
ipa         : DEBUG    stdout=
ipa         : DEBUG    stderr=Operation failed! PrincipalName not found.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. Install Freeipa server and provision
2. Attempt to install adtrust


Attached complete -d output from attempt to configure service.

Comment 1 William Brown 2014-08-10 11:34:38 UTC
Seemed to be a DNS problem. Sorry for the noise.

Note You need to log in before you can comment on or make changes to this bug.