Hide Forgot
Description of problem: # ipactl status Directory Service: RUNNING KDC Service: RUNNING KPASSWD Service: RUNNING DNS Service: RUNNING HTTP Service: RUNNING CA Service: RUNNING # ipactl stop Stopping CA Service Stopping pki-ca: [ OK ] Stopping HTTP Service Stopping httpd: [ OK ] Stopping DNS Service Stopping named: . [ OK ] Stopping KPASSWD Service Stopping Kerberos 5 Admin Server: [ OK ] Stopping KDC Service Stopping Kerberos 5 KDC: [ OK ] Stopping Directory Service Shutting down dirsrv: PKI-IPA... [ OK ] TESTRELM-COM... [ OK ] # ipactl start Starting Directory Service Starting dirsrv: PKI-IPA... [ OK ] TESTRELM-COM... [ OK ] Starting KDC Service Starting Kerberos 5 KDC: [ OK ] Starting KPASSWD Service Starting Kerberos 5 Admin Server: [ OK ] Starting DNS Service Starting named: [ OK ] Starting HTTP Service Starting httpd: [Mon Jan 30 11:07:04 2012] [warn] worker ajp://localhost:9447/ already used by another worker [Mon Jan 30 11:07:04 2012] [warn] worker ajp://localhost:9447/ already used by another worker [ OK ] Starting CA Service Starting pki-ca: [ OK ] Version-Release number of selected component (if applicable): ipa-server-2.2.0-101.20120127T0607zgit6863b8f.el6.x86_64 How reproducible: always Steps to Reproduce: 1. 2. 3. Actual results: Expected results: Additional info: note warning displayed on start is logged in another bug
Upstream ticket: https://fedorahosted.org/freeipa/ticket/2333
ipa_kpasswd went away but a new service is being run in its stead, the standard kadmind service. Simo purposely set the name to kpasswd.
# ps -ef | grep krb5kdc root 4760 1 0 11:12 ? 00:00:00 /usr/sbin/krb5kdc -r TESTRELM.COM -P /var/run/krb5kdc.pid root 5613 8022 0 11:53 pts/0 00:00:00 grep krb5kdc # ps -ef | grep kadmind root 4776 1 0 11:12 ? 00:00:00 /usr/sbin/kadmind -P /var/run/kadmind.pid root 5619 8022 0 11:53 pts/0 00:00:00 grep kadmind # ps -ef | grep kpasswd root 5623 8022 0 11:53 pts/0 00:00:00 grep kpasswd This is confusing ....
Simo, QE finds your choice of KPASSWD to mean kadmind confusing. I have to say I agree. What was your rationale?
A) it was the existing service name, by not changing it we do not have a problem upgrading. B) we really use kadmin exclusively for the kpasswd functionality, all other functions are basically disabled in the ipa-kdb backend.
If this is resolved, I believe we should just close this BZ as wontfix. It is already closed as wontfix upstream.
It is still confusing as someone may look for this service because it is listed as a running or stopped service.. If I did a "ipactl status" and it said the kpasswd was not running ... I would try "service kpasswd start" and ... it would fail. This is not resolved.
I don't think the names we display will be confused with an actual service name considering we don't use actual service names in the output.
The current output looks like this. This explains what I mean about service names not being in the output: Directory Service: RUNNING KDC Service: RUNNING KPASSWD Service: RUNNING DNS Service: RUNNING MEMCACHE Service: RUNNING HTTP Service: RUNNING CA Service: RUNNING None of these are actual unix service names.
okay, will change my tests and lets mark this resolved