Bug 2004646
| Summary: | RFE: Improve error message with more detail for ipa-replica-install command | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Hemant B Khot <hkhot> | |
| Component: | ipa | Assignee: | Trivino <ftrivino> | |
| Status: | CLOSED ERRATA | QA Contact: | ipa-qe <ipa-qe> | |
| Severity: | medium | Docs Contact: | ||
| Priority: | unspecified | |||
| Version: | 8.3 | CC: | frenaud, ftrivino, mpolovka, peter.vreman, rcritten, rjeffman, sumenon, tscherf | |
| Target Milestone: | rc | Keywords: | FutureFeature, Triaged | |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
|
| Hardware: | All | |||
| OS: | Linux | |||
| Whiteboard: | ||||
| Fixed In Version: | ipa-4.9.10-1.module+el8.7.0+15691+2b2c1dd5 | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | ||
| Clone Of: | ||||
| : | 2089750 (view as bug list) | Environment: | ||
| Last Closed: | 2022-11-08 09:35:45 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 2089750 | |||
Easy to fix. In ipaserver/install/server/replicainstall.py, in the method promote_check (line 1024), the installer looks for an existing replication agreement and prints an error message:
----- 8< -----
# Check that we don't already have a replication agreement
if replman.get_replication_agreement(config.host_name):
msg = ("A replication agreement for this host already exists. "
"It needs to be removed.\n"
"Run this command:\n"
" %% ipa-replica-manage del {host} --force"
.format(host=config.host_name))
raise ScriptError(msg, rval=3)
----- >8 -----
The msg needs to be changed into "Run this command on any working server: %% ipa server-del {host} --force"
- ipa server-del instead of ipa-replica-manage del because only domain-level1 is now supported
- and the commands needs to be run on a working server, not on the host where ipa-replica-install failed
fixed upstream: https://github.com/freeipa/freeipa/pull/6274 Moving to POST. Fixed upstream: master: https://pagure.io/freeipa/c/5457fb7f7efef368b4e6db44f644b909d14c3f44 ipa-4-9: https://pagure.io/freeipa/c/c03a8c3c06562c128aac6be506274995cea74948 Test added upstream master: https://pagure.io/freeipa/c/ce50d2255f9f7adaebd221e462f75cbe79366d75 https://pagure.io/freeipa/c/94dd9ef1d69e30f687686d8584b6b79880a098f3 ipa-4-9: https://pagure.io/freeipa/c/352b9dfb49bdf1c70a8de9ed7287387417580c86 https://pagure.io/freeipa/c/58ddcffc412f7dd5cc762bd6f80faa07fcedf7ec Pre-verified using automation from ipatests/test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer:test_replica_install_existing_agreement with the package ipa-server-4.9.10-1.module+el8.7.0+15691+2b2c1dd5.x86_64 Passed test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer::()::test_replica_install_against_server_without_ca Passed test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer::()::test_replica_install_against_server_without_kra Passed test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer::()::test_replica_install_against_server Passed test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer::()::test_replica_install_existing_agreement Therefore marking as verified: tested. Full test log is an attachment of this BZ. Verified using automation from ipatests/test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer:test_replica_install_existing_agreement with a package ipa-server-4.9.10-4.module+el8.7.0+15926+daa9f08b.x86_64 from the nightly repository. Passed test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer::()::test_replica_install_against_server_without_ca Passed test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer::()::test_replica_install_against_server_without_kra Passed test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer::()::test_replica_install_against_server Passed test_integration/test_installation.py::TestInstallReplicaAgainstSpecificServer::()::test_replica_install_existing_agreement Full pytest log is an attachment of this BZ. Marking as verified. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (idm:client and idm:DL1 bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2022:7540 |
Reproducer to get into such error situation: - Use external DNS server (we use Windows AD based DNS servers) and not the internal DNS servers of IPA - Install a RHEL7 IPA server and have it working (we have it also AD connected, but for this case it does not matter) - Confirm the SRV records point to RHEL7 - Install a RHEL8 server - Switch on the external DNS the SRV records already tp point to RHEL8 server - Install RHEL8 IPA server without the --server option to have it using the SRV records (that already point the the RHEL8 server that is being installed) - Run on RHEL8 ipa-server-install -uninstall to prepare to try again - Install RHEL8 IPA server now with the --server=RHEL7-fqdn - Now you have the failure that the replica-agreement already exists from the first installation that was failing because the SRV records were point to the not yet install RHEL8 IPA server In our installation i found out that mentioned command on replica-agreement had to be executed on the RHEL7-IPA server where the agreement was also already created. That means that the error is missing important information that the replica-agreement has to be deleted from the other end of the agreement. Expected error my real-world use case, the information missing i added in <<...>>: ~~~ The ipa-replica-install command failed, exception: ScriptError: A replication agreement for this host <<new.server.example.com> already exists <<on working.server.example.com>>. Run this command <<on workin.server.example.com to remove the replication agreement>>: %% ipa-replica-manage del new.server.example.com --force ~~~