Bug 636682 - Terminal crash of 389 LDAP server when running AD sync command
Summary: Terminal crash of 389 LDAP server when running AD sync command
Keywords:
Status: CLOSED DUPLICATE of bug 634561
Alias: None
Product: freeIPA
Classification: Retired
Component: ipa-server
Version: 2.0
Hardware: x86_64
OS: Linux
low
urgent
Target Milestone: ---
Assignee: Rich Megginson
QA Contact: Chandrasekar Kannan
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-09-22 21:48 UTC by Steven
Modified: 2015-01-04 23:44 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2010-09-22 22:29:18 UTC
Embargoed:


Attachments (Terms of Use)

Description Steven 2010-09-22 21:48:35 UTC
Description of problem:

The 389 LDAP server shuts down every time.

Version-Release number of selected component (if applicable):

IPA v 2

This is Fedora 13 with the yum repo setup as per your web site...

389-ds-base-1.2.6-1.fc13.x86_64
ipa-server-1.2.2-4.fc13.x86_64


How reproducible:

Every time


Steps to Reproduce:
1. Install IPA via repo onto CR13
2. Start setting up as per Documentation
3. Section 4.4 run command to AD sync,

After I do the sync command,

ipa-replica-manage add --winsync --binddn cn=administrator,cn=users,dc=example,dc=com --bindpw <domain admin password>  \ --cacert /path/to/certfile.cer adserver.example.com --passsync <domain admin password> -v

The output to the logs as below occurs and LDAP searches etc no longer work.
  
Actual results:

LDAP seems to kick off a shutdown but never completes.

Expected results:

Ad sync takes place.

Additional info:

8><-------


Can you reliably reproduce this behavior after restarting directory server?


8><--------

Yes it appears so..........

> =============error
> [22/Sep/2010:15:58:16 +1200] - slapd shutting down - signaling 
> operation threads
> [22/Sep/2010:15:58:16 +1200] - slapd shutting down - closing down 
> internal subsystems and plugins
> [22/Sep/2010:16:08:31 +1200] NSMMReplicationPlugin - error in 
> windows_conn_get_search_result, rc=-1
> [22/Sep/2010:16:08:31 +1200] NSMMReplicationPlugin - 
> agmt="cn=meTovuwwincodc00001.vuw.ac.nz636" (vuwwincodc00001:636): 
> Failed to get search operation: LDAP error 81 (Can't contact LDAP 
> server)
> [22/Sep/2010:16:08:31 +1200] NSMMReplicationPlugin - failed to send 
> dirsync search request: 2
> [22/Sep/2010:16:08:32 +1200] - Waiting for 4 database threads to stop
> [22/Sep/2010:16:08:32 +1200] - All database threads now stopped
> [22/Sep/2010:16:08:32 +1200] - slapd stopped.
> =============
>
> =============access
> [22/Sep/2010:15:57:41 +1200] conn=6 op=15 SRCH base="dc=vuw,dc=ac,dc=nz" scope=2 filter="(&(cn=pulse-rt)(objectClass=posixGroup))" attrs="objectClass cn userPassword gidNumber member nsUniqueId modifyTimestamp"
> [22/Sep/2010:15:57:41 +1200] conn=6 op=15 RESULT err=0 tag=101 
> nentries=0 etime=0
> [22/Sep/2010:15:58:16 +1200] conn=8 fd=70 slot=70 SSL connection from 
> 130.195.53.104 to 130.195.53.104
> [22/Sep/2010:15:58:16 +1200] conn=8 SSL 256-bit AES
> [22/Sep/2010:15:58:16 +1200] conn=8 op=0 BIND dn="cn=directory 
> manager" method=128 version=3
> [22/Sep/2010:15:58:16 +1200] conn=8 op=0 RESULT err=0 tag=97 nentries=0 etime=0 dn="cn=directory manager"
> [22/Sep/2010:15:58:16 +1200] conn=8 op=1 SRCH base="cn=config" scope=0 filter="(objectClass=*)" attrs="nsslapd-instancedir nsslapd-errorlog nsslapd-certdir nsslapd-schemadir"
> [22/Sep/2010:15:58:16 +1200] conn=8 op=1 RESULT err=0 tag=101 
> nentries=1 etime=0
> [22/Sep/2010:15:58:16 +1200] conn=8 op=2 SRCH base="cn=config,cn=ldbm database,cn=plugins,cn=config" scope=0 filter="(objectClass=*)" attrs="nsslapd-directory"
> [22/Sep/2010:15:58:16 +1200] conn=8 op=2 RESULT err=0 tag=101 
> nentries=1 etime=0
>

=========================



8><------------

> access log,
>
> [22/Sep/2010:14:22:39 +1200] conn=48 fd=65 slot=65 connection from 
> 127.0.0.1 to 127.0.0.1
> [22/Sep/2010:14:22:39 +1200] conn=48 op=0 BIND dn="" method=128 
> version=3
> [22/Sep/2010:14:22:39 +1200] conn=48 op=0 RESULT err=0 tag=97 nentries=0 etime=0 dn=""
> [22/Sep/2010:14:22:39 +1200] conn=48 op=1 SRCH base="dc=vuw,dc=ac,dc=nz" scope=2 filter="(&(cn=pulse-rt)(objectClass=posixGroup))" attrs="objectClass cn userPassword gidNumber member nsUniqueId modifyTimestamp"
> [22/Sep/2010:14:22:39 +1200] conn=48 op=1 RESULT err=0 tag=101 
> nentries=0 etime=0
> [22/Sep/2010:14:23:57 +1200] conn=49 fd=66 slot=66 SSL connection from 
> 130.195.53.104 to 130.195.53.104
> [22/Sep/2010:14:23:57 +1200] conn=49 SSL 256-bit AES
> [22/Sep/2010:14:23:57 +1200] conn=49 op=0 BIND dn="cn=directory 
> manager" method=128 version=3
> [22/Sep/2010:14:23:57 +1200] conn=49 op=0 RESULT err=49 tag=97 
> nentries=0 etime=0
> [22/Sep/2010:14:23:57 +1200] conn=49 op=1 UNBIND
> [22/Sep/2010:14:23:57 +1200] conn=49 op=1 fd=66 closed - U1
> [22/Sep/2010:14:24:02 +1200] conn=50 fd=66 slot=66 SSL connection from 
> 130.195.53.104 to 130.195.53.104
> [22/Sep/2010:14:24:02 +1200] conn=50 SSL 256-bit AES
> [22/Sep/2010:14:24:02 +1200] conn=50 op=0 BIND dn="cn=directory 
> manager" method=128 version=3
> [22/Sep/2010:14:24:02 +1200] conn=50 op=0 RESULT err=0 tag=97 nentries=0 etime=0 dn="cn=directory manager"
> [22/Sep/2010:14:24:02 +1200] conn=50 op=1 SRCH base="cn=config" scope=0 filter="(objectClass=*)" attrs="nsslapd-instancedir nsslapd-errorlog nsslapd-certdir nsslapd-schemadir"
> [22/Sep/2010:14:24:02 +1200] conn=50 op=1 RESULT err=0 tag=101 
> nentries=1 etime=0
> [22/Sep/2010:14:24:02 +1200] conn=50 op=2 SRCH base="cn=config,cn=ldbm database,cn=plugins,cn=config" scope=0 filter="(objectClass=*)" attrs="nsslapd-directory"
> [22/Sep/2010:14:24:02 +1200] conn=50 op=2 RESULT err=0 tag=101 
> nentries=1 etime=0
> [22/Sep/2010:14:24:02 +1200] conn=50 op=3 SRCH base="cn=mapping 
> tree,cn=config" scope=2 
> filter="(|(objectClass=nsDSWindowsReplicationAgreement)(objectClass=ns
> ds5ReplicationAgreement))" attrs=ALL
> [22/Sep/2010:14:24:02 +1200] conn=50 op=3 RESULT err=0 tag=101 
> nentries=1 etime=0
> [22/Sep/2010:14:24:02 +1200] conn=50 op=4 SRCH 
> base="cn=meTovuwwincodc00001.vuw.ac.nz636, cn=replica, 
> cn=\22dc=vuw,dc=ac,dc=nz\22, cn=mapping tree, cn=config" scope=2 
> filter="(objectClass=*)" attrs=ALL
> [22/Sep/2010:14:24:02 +1200] conn=50 op=4 RESULT err=0 tag=101 
> nentries=1 etime=0
> [22/Sep/2010:14:24:02 +1200] conn=50 op=5 UNBIND
> [22/Sep/2010:14:24:02 +1200] conn=50 op=5 fd=66 closed - U1
> [22/Sep/2010:14:33:36 +1200] conn=51 fd=66 slot=66 SSL connection from 
> 130.195.53.104 to 130.195.53.104
> [22/Sep/2010:14:33:36 +1200] conn=51 SSL 256-bit AES
> [22/Sep/2010:14:33:36 +1200] conn=51 op=0 BIND dn="cn=directory 
> manager" method=128 version=3
> [22/Sep/2010:14:33:36 +1200] conn=51 op=0 RESULT err=0 tag=97 nentries=0 etime=0 dn="cn=directory manager"
> [22/Sep/2010:14:33:36 +1200] conn=51 op=1 SRCH base="cn=config" scope=0 filter="(objectClass=*)" attrs="nsslapd-instancedir nsslapd-errorlog nsslapd-certdir nsslapd-schemadir"
> [22/Sep/2010:14:33:36 +1200] conn=51 op=1 RESULT err=0 tag=101 
> nentries=1 etime=0
> [22/Sep/2010:14:33:36 +1200] conn=51 op=2 SRCH base="cn=config,cn=ldbm database,cn=plugins,cn=config" scope=0 filter="(objectClass=*)" attrs="nsslapd-directory"
> [22/Sep/2010:14:33:36 +1200] conn=51 op=2 RESULT err=0 tag=101 
> nentries=1 etime=0
>  

(From: Rich Megginson to me.....)
 
The time corresponds to this from the errors log:
[22/Sep/2010:14:33:36 +1200] - slapd shutting down - signaling operation threads
[22/Sep/2010:14:33:36 +1200] - slapd shutting down - closing down internal subsystems and plugins

But a SRCH operation should not trigger a shutdown.

Not sure what's going on here.

Comment 1 Rich Megginson 2010-09-22 22:29:18 UTC

*** This bug has been marked as a duplicate of bug 634561 ***


Note You need to log in before you can comment on or make changes to this bug.