hello all:
I am trying to install the freeipa-server(4.7.1) package on Debian9, which is
now failing, the failed message is pkispawn failed. The installation output is as follows, after running apt install
freeipa-server. I want to know the effective way of installation freeipa-server
on debian. Can you provide the way of compile the freeipa project?
1. Debian9 system info.
Linux root 4.9.0-9-amd64 #1 SMP Debian 4.9.168-1 (2019-04-12) x86_64 GNU/Linux
2. Freeipa-server deb info.
freeipa-admintools_4.7.1-3_amd64.deb freeipa-tests_4.7.1-3_all.deb
freeipa-client_4.7.1-3_amd64.deb pki-tools_10.6.8-2_amd64.deb
freeipa-common_4.7.1-3_all.deb python-ipaclient_4.7.1-3_all.deb
freeipa-server_4.7.1-3_amd64.deb python-ipalib_4.7.1-3_all.deb
freeipa-server-dns_4.7.1-3_all.deb python-ipaserver_4.7.1-3_all.deb
freeipa-server-trust-ad_4.7.1-3_amd64.deb python-ipatests_4.7.1-3_all.deb
3. The error log as follows.
ipa-server-install
2019-07-11T11:33:19Z DEBUG Starting external process
2019-07-11T11:33:19Z DEBUG args=['/usr/sbin/pkispawn', '-s', 'CA', '-f', '/tmp/tmpYHBX9A']
2019-07-11T11:34:20Z DEBUG Process finished, return code=1
2019-07-11T11:34:20Z DEBUG stdout=Starting pki-tomcatd (via systemctl): pki-tomcatd.service.
Log file: /var/log/pki/pki-ca-spawn.20190711073319.log
Loading deployment configuration from /tmp/tmpYHBX9A.
WARNING: The 'pki_pin' in [CA] has been deprecated. Use 'pki_server_database_password' instead.
Installing CA into /var/lib/pki/pki-tomcat.
Storing deployment configuration into /etc/dogtag/tomcat/pki-tomcat/ca/deployment.cfg.
Installation failed: server failed to restart
2019-07-11T11:34:20Z DEBUG stderr=pkispawn : ERROR Server did not start after 60s
configuration : ERROR Server failed to restart
2019-07-11T11:34:20Z CRITICAL Failed to configure CA instance: CalledProcessError(Command ['/usr/sbi
n/pkispawn', '-s', 'CA', '-f', '/tmp/tmpYHBX9A'] returned non-zero exit status 1: u'pkispawn :
ERROR Server did not start after 60s\nconfiguration : ERROR Server failed to restart\n')
2019-07-11T11:34:20Z CRITICAL See the installation logs and the following files/directories for more
information:
2019-07-11T11:34:20Z CRITICAL /var/log/pki/pki-tomcat
2019-07-11T11:34:20Z DEBUG Traceback (most recent call last):
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 605, in start_creation
run_step(full_msg, method)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 591, in run_step
method()
File "/usr/lib/python2.7/dist-packages/ipaserver/install/cainstance.py", line 669, in __spawn_inst
ance
pki_pin)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/dogtaginstance.py", line 166, in spawn_in
stance
self.handle_setup_error(e)
[2019/7/12 16:01] wangyaliang (13985, Cloud):
File "/usr/lib/python2.7/dist-packages/ipaserver/install/...
File "/usr/lib/python2.7/dist-packages/ipaserver/install/dogtaginstance.py", line 407, in handle_s
etup_error
raise RuntimeError("%s configuration failed." % self.subsystem)
RuntimeError: CA configuration failed.
2019-07-11T11:34:20Z DEBUG [error] RuntimeError: CA configuration failed.
2019-07-11T11:34:20Z DEBUG File "/usr/lib/python2.7/dist-packages/ipapython/admintool.py", line 17
9, in execute
return_value = self.run()
File "/usr/lib/python2.7/dist-packages/ipapython/install/cli.py", line 347, in run
return cfgr.run()
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 360, in run
return self.execute()
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 386, in execute
for rval in self._executor():
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 431, in __runner
exc_handler(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 460, in _handle_execute_ex
ception
self._handle_exception(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 450, in _handle_exception
six.reraise(*exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 421, in __runner
step()
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 418, in <lambda>
step = lambda: next(self.__gen)
File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 81, in run_generator_with_
yield_from
six.reraise(*exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 59, in run_generator_with_
yield_from
value = gen.send(prev_value)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 655, in _configure
next(executor)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 431, in __runner
exc_handler(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 460, in _handle_execute_ex
ception
self._handle_exception(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 518, in _handle_exception
self.__parent._handle_exception(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 450, in _handle_exception
six.reraise(*exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 515, in _handle_exception
super(ComponentBase, self)._handle_exception(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 450, in _handle_exception
six.reraise(*exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 421, in __runner
step()
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 418, in <lambda>
step = lambda: next(self.__gen)
File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 81, in run_generator_with_
yield_from
six.reraise(*exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 59, in run_generator_with_
yield_from
value = gen.send(prev_value)
File "/usr/lib/python2.7/dist-packages/ipapython/install/common.py", line 65, in _install
for unused in self._installer(self.parent):
File "/usr/lib/python2.7/dist-packages/ipaserver/install/server/__init__.py", line 550, in main
master_install(self)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/server/install.py", line 253, in decorate
d
func(installer)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/server/install.py", line 842, in install
ca.install_step_0(False, None, options, custodia=custodia)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/ca.py", line 318, in install_step_0
use_ldaps=standalone)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/cainstance.py", line 484, in configure_in
stance
self.start_creation(runtime=runtime)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 605, in start_creation
run_step(full_msg, method)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 591, in run_step
method()
File "/usr/lib/python2.7/dist-packages/ipaserver/install/cainstance.py", line 669, in __spawn_inst
ance
pki_pin)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/dogtaginstance.py", line 166, in spawn_in
stance
self.handle_setup_error(e)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/dogtaginstance.py", line 407, in handle_s
etup_error
raise RuntimeError("%s configuration failed." % self.subsystem)
2019-07-11T11:34:20Z DEBUG The ipa-server-install command failed, exception: RuntimeError: CA config
uration failed.
2019-07-11T11:34:20Z ERROR CA configuration failed.
2019-07-11T11:34:20Z ERROR The ipa-server-install command failed. See /var/log/ipaserver-install.log
for more information
4. Pkispawn error info.
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/caAuditSigningCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/caAuditSigningCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... cp -p /usr/share/pki/ca/conf/caCert.profile /etc/pki/pki-tomcat/ca/caCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/caCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/caCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... cp -p /usr/share/pki/ca/conf/caOCSPCert.profile /etc/pki/pki-tomcat/ca/caOCSPCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/caOCSPCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/caOCSPCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... cp -p /usr/share/pki/ca/conf/rsaServerCert.profile /etc/pki/pki-tomcat/ca/serverCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/serverCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/serverCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... cp -p /usr/share/pki/ca/conf/rsaSubsystemCert.profile /etc/pki/pki-tomcat/ca/subsystemCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/subsystemCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/subsystemCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... copying '/usr/share/pki/ca/conf/proxy.conf' --> '/etc/pki/pki-tomcat/ca/proxy.conf' with slot substitution
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/proxy.conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/proxy.conf
2019-07-08 03:58:07 pkispawn : INFO ....... ln -s /var/lib/pki/pki-tomcat/alias /var/lib/pki/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown -h 111:117 /var/lib/pki/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : INFO ....... ln -s /etc/pki/pki-tomcat/ca /var/lib/pki/pki-tomcat/ca/conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown -h 111:117 /var/lib/pki/pki-tomcat/ca/conf
2019-07-08 03:58:07 pkispawn : INFO ....... ln -s /var/log/pki/pki-tomcat/ca /var/lib/pki/pki-tomcat/ca/logs
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown -h 111:117 /var/lib/pki/pki-tomcat/ca/logs
2019-07-08 03:58:07 webapp : INFO Creating webapp
2019-07-08 03:58:07 pkispawn : INFO ....... mkdir -p /var/lib/pki/pki-tomcat/ca/webapps
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 770 /var/lib/pki/pki-tomcat/ca/webapps
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /var/lib/pki/pki-tomcat/ca/webapps
2019-07-08 03:58:07 pkispawn : INFO ....... setting ownerships, permissions, and acls on '/var/lib/pki/pki-tomcat/ca/webapps'
2019-07-08 03:58:07 nssdb : INFO Creating NSS database
2019-07-08 03:58:07 pki.server : INFO Loading instance: pki-tomcat
2019-07-08 03:58:07 pki.server : INFO Loading instance registry: /etc/dogtag/tomcat/pki-tomcat/pki-tomcat
2019-07-08 03:58:07 pki.server : INFO Loading subsystem: ca
2019-07-08 03:58:07 pki.server : INFO Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg
2019-07-08 03:58:07 nssdb : INFO Creating password config: /etc/pki/pki-tomcat/password.conf
2019-07-08 03:58:07 nssdb : INFO Creating password file: /etc/pki/pki-tomcat/pfile
2019-07-08 03:58:07 pkispawn : INFO ....... modifying '/etc/pki/pki-tomcat/password.conf'
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/password.conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/password.conf
2019-07-08 03:58:07 pkispawn : INFO ....... executing 'certutil -N -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/pfile'
2019-07-08 03:58:07 pkispawn : INFO ....... rm -f /etc/pki/pki-tomcat/pfile
2019-07-08 03:58:07 pki.server : INFO Getting signing cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting ocsp_signing cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting sslserver cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting subsystem cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting audit_signing cert info for ca from CS.cfg
2019-07-08 03:58:07 pkispawn : INFO ....... mkdir -p /root/.dogtag/pki-tomcat/ca
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 755 /root/.dogtag/pki-tomcat/ca
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 0:0 /root/.dogtag/pki-tomcat/ca
2019-07-08 03:58:07 nssdb : INFO Creating password file: /root/.dogtag/pki-tomcat/ca/password.conf
2019-07-08 03:58:07 pkispawn : INFO ....... modifying '/root/.dogtag/pki-tomcat/ca/password.conf'
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /root/.dogtag/pki-tomcat/ca/password.conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 0:0 /root/.dogtag/pki-tomcat/ca/password.conf
2019-07-08 03:58:07 pkispawn : INFO ....... generating '/root/.dogtag/pki-tomcat/ca/pkcs12_password.conf'
2019-07-08 03:58:07 pkispawn : INFO ....... modifying '/root/.dogtag/pki-tomcat/ca/pkcs12_password.conf'
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf
2019-07-08 03:58:07 pkispawn : INFO ....... mkdir -p /root/.dogtag/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 770 /root/.dogtag/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 0:0 /root/.dogtag/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : INFO ....... executing 'certutil -N -d /root/.dogtag/pki-tomcat/ca/alias -f /root/.dogtag/pki-tomcat/ca/password.conf'
2019-07-08 03:58:07 selinux : INFO SELinux disabled
2019-07-08 03:58:07 keygen : INFO Generating keys
2019-07-08 03:58:07 pki.server : INFO Loading instance: pki-tomcat
2019-07-08 03:58:07 pki.server : INFO Loading instance registry: /etc/dogtag/tomcat/pki-tomcat/pki-tomcat
2019-07-08 03:58:07 pki.server : INFO Loading password config: /etc/pki/pki-tomcat/password.conf
2019-07-08 03:58:07 pki.server : INFO Loading subsystem: ca
2019-07-08 03:58:07 pki.server : INFO Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting signing cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting signing cert info for ca from NSS database
2019-07-08 03:58:07 pki.nssdb : DEBUG Command: certutil -L -d /var/lib/pki/pki-tomcat/alias -f /tmp/tmpQ8ZCeb/password.txt -n caSigningCert cert-pki-ca -a
2019-07-08 03:58:07 keygen : INFO Generating ca_signing CSR in /root/ipa.csr
2019-07-08 03:58:07 pki.nssdb : DEBUG Command: openssl rand -out /tmp/tmpv1RVD7/noise.bin 2048
2019-07-08 03:58:07 pki.nssdb : DEBUG Command: certutil -R -d /var/lib/pki/pki-tomcat/alias -f /tmp/tmpv1RVD7/password.txt -s CN=Certificate Authority,O=EXAMPLE.COM -o /tmp/tmpv1RVD7/request.bin -z /tmp/tmpv1RVD7/noise.bin -k rsa -g 2048 -Z SHA256 --keyUsage certSigning,crlSigning,critical,digitalSignature,nonRepudiation -2
2019-07-08 03:58:07 pkispawn : DEBUG ....... Error Type: CalledProcessError
2019-07-08 03:58:07 pkispawn : DEBUG ....... Error Message: Command '['BtoA', '/tmp/tmpv1RVD7/request.bin', '/tmp/tmpv1RVD7/request.b64']' returned non-zero exit status 1
2019-07-08 03:58:07 pkispawn : DEBUG ....... File "/usr/lib/python2.7/dist-packages/pki/server/pkispawn.py", line 546, in main
scriptlet.spawn(deployer)
File "/usr/lib/python2.7/dist-packages/pki/server/deployment/scriptlets/keygen.py", line 468, in spawn
self.generate_system_cert_requests(deployer, subsystem)
File "/usr/lib/python2.7/dist-packages/pki/server/deployment/scriptlets/keygen.py", line 433, in generate_system_cert_requests
self.generate_ca_signing_csr(deployer, subsystem)
File "/usr/lib/python2.7/dist-packages/pki/server/deployment/scriptlets/keygen.py", line 176, in generate_ca_signing_csr
generic_exts=generic_exts
File "/usr/lib/python2.7/dist-packages/pki/server/deployment/scriptlets/keygen.py", line 113, in generate_csr
generic_exts=generic_exts)
File "/usr/lib/python2.7/dist-packages/pki/nssdb.py", line 613, in create_request
'BtoA', binary_request_file, b64_request_file])
File "/usr/lib/python2.7/subprocess.py", line 190, in check_call
raise CalledProcessError(retcode, cmd)
Thanks.
1292865949--- via FreeIPA-users wrote:
hello all:
I am trying to install the freeipa-server(4.7.1) package on Debian9, which is
now failing, the failed message is pkispawn failed. The installation output is as follows, after running apt install
freeipa-server. I want to know the effective way of installation freeipa-server
on debian. Can you provide the way of compile the freeipa project?
- Debian9 system info.
Linux root 4.9.0-9-amd64 #1 SMP Debian 4.9.168-1 (2019-04-12) x86_64 GNU/Linux
- Freeipa-server deb info.
freeipa-admintools_4.7.1-3_amd64.deb freeipa-tests_4.7.1-3_all.deb
freeipa-client_4.7.1-3_amd64.deb pki-tools_10.6.8-2_amd64.deb
freeipa-common_4.7.1-3_all.deb python-ipaclient_4.7.1-3_all.deb
freeipa-server_4.7.1-3_amd64.deb python-ipalib_4.7.1-3_all.deb
freeipa-server-dns_4.7.1-3_all.deb python-ipaserver_4.7.1-3_all.deb
freeipa-server-trust-ad_4.7.1-3_amd64.deb python-ipatests_4.7.1-3_all.deb
- The error log as follows.
ipa-server-install
2019-07-11T11:33:19Z DEBUG Starting external process
2019-07-11T11:33:19Z DEBUG args=['/usr/sbin/pkispawn', '-s', 'CA', '-f', '/tmp/tmpYHBX9A']
2019-07-11T11:34:20Z DEBUG Process finished, return code=1
2019-07-11T11:34:20Z DEBUG stdout=Starting pki-tomcatd (via systemctl): pki-tomcatd.service.
Log file: /var/log/pki/pki-ca-spawn.20190711073319.log
Loading deployment configuration from /tmp/tmpYHBX9A.
WARNING: The 'pki_pin' in [CA] has been deprecated. Use 'pki_server_database_password' instead.
Installing CA into /var/lib/pki/pki-tomcat.
Storing deployment configuration into /etc/dogtag/tomcat/pki-tomcat/ca/deployment.cfg.
Installation failed: server failed to restart
2019-07-11T11:34:20Z DEBUG stderr=pkispawn : ERROR Server did not start after 60s
configuration : ERROR Server failed to restart
2019-07-11T11:34:20Z CRITICAL Failed to configure CA instance: CalledProcessError(Command ['/usr/sbi
n/pkispawn', '-s', 'CA', '-f', '/tmp/tmpYHBX9A'] returned non-zero exit status 1: u'pkispawn :
ERROR Server did not start after 60s\nconfiguration : ERROR Server failed to restart\n')
2019-07-11T11:34:20Z CRITICAL See the installation logs and the following files/directories for more
information:
2019-07-11T11:34:20Z CRITICAL /var/log/pki/pki-tomcat
2019-07-11T11:34:20Z DEBUG Traceback (most recent call last):
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 605, in start_creation
run_step(full_msg, method)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 591, in run_step
method()
File "/usr/lib/python2.7/dist-packages/ipaserver/install/cainstance.py", line 669, in __spawn_inst
ance
pki_pin)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/dogtaginstance.py", line 166, in spawn_in
stance
self.handle_setup_error(e) [2019/7/12 16:01] wangyaliang (13985, Cloud):
File "/usr/lib/python2.7/dist-packages/ipaserver/install/...
File "/usr/lib/python2.7/dist-packages/ipaserver/install/dogtaginstance.py", line 407, in handle_s
etup_error
raise RuntimeError("%s configuration failed." % self.subsystem)
RuntimeError: CA configuration failed.
2019-07-11T11:34:20Z DEBUG [error] RuntimeError: CA configuration failed.
2019-07-11T11:34:20Z DEBUG File "/usr/lib/python2.7/dist-packages/ipapython/admintool.py", line 17
9, in execute
return_value = self.run()
File "/usr/lib/python2.7/dist-packages/ipapython/install/cli.py", line 347, in run
return cfgr.run()
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 360, in run
return self.execute()
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 386, in execute
for rval in self._executor():
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 431, in __runner
exc_handler(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 460, in _handle_execute_ex
ception
self._handle_exception(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 450, in _handle_exception
six.reraise(*exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 421, in __runner
step()
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 418, in <lambda>
step = lambda: next(self.__gen)
File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 81, in run_generator_with_
yield_from
six.reraise(*exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 59, in run_generator_with_
yield_from
value = gen.send(prev_value)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 655, in _configure
next(executor)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 431, in __runner
exc_handler(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 460, in _handle_execute_ex
ception
self._handle_exception(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 518, in _handle_exception
self.__parent._handle_exception(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 450, in _handle_exception
six.reraise(*exc_info) File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 515, in _handle_exception super(ComponentBase, self)._handle_exception(exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 450, in _handle_exception
six.reraise(*exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 421, in __runner
step()
File "/usr/lib/python2.7/dist-packages/ipapython/install/core.py", line 418, in <lambda>
step = lambda: next(self.__gen)
File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 81, in run_generator_with_
yield_from
six.reraise(*exc_info)
File "/usr/lib/python2.7/dist-packages/ipapython/install/util.py", line 59, in run_generator_with_
yield_from
value = gen.send(prev_value)
File "/usr/lib/python2.7/dist-packages/ipapython/install/common.py", line 65, in _install
for unused in self._installer(self.parent):
File "/usr/lib/python2.7/dist-packages/ipaserver/install/server/__init__.py", line 550, in main
master_install(self)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/server/install.py", line 253, in decorate
d
func(installer)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/server/install.py", line 842, in install
ca.install_step_0(False, None, options, custodia=custodia)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/ca.py", line 318, in install_step_0
use_ldaps=standalone)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/cainstance.py", line 484, in configure_in
stance
self.start_creation(runtime=runtime)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 605, in start_creation
run_step(full_msg, method)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/service.py", line 591, in run_step
method()
File "/usr/lib/python2.7/dist-packages/ipaserver/install/cainstance.py", line 669, in __spawn_inst
ance
pki_pin)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/dogtaginstance.py", line 166, in spawn_in
stance
self.handle_setup_error(e)
File "/usr/lib/python2.7/dist-packages/ipaserver/install/dogtaginstance.py", line 407, in handle_s
etup_error
raise RuntimeError("%s configuration failed." % self.subsystem)
2019-07-11T11:34:20Z DEBUG The ipa-server-install command failed, exception: RuntimeError: CA config
uration failed.
2019-07-11T11:34:20Z ERROR CA configuration failed.
2019-07-11T11:34:20Z ERROR The ipa-server-install command failed. See /var/log/ipaserver-install.log
for more information
- Pkispawn error info.
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/caAuditSigningCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/caAuditSigningCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... cp -p /usr/share/pki/ca/conf/caCert.profile /etc/pki/pki-tomcat/ca/caCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/caCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/caCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... cp -p /usr/share/pki/ca/conf/caOCSPCert.profile /etc/pki/pki-tomcat/ca/caOCSPCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/caOCSPCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/caOCSPCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... cp -p /usr/share/pki/ca/conf/rsaServerCert.profile /etc/pki/pki-tomcat/ca/serverCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/serverCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/serverCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... cp -p /usr/share/pki/ca/conf/rsaSubsystemCert.profile /etc/pki/pki-tomcat/ca/subsystemCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/subsystemCert.profile
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/subsystemCert.profile
2019-07-08 03:58:07 pkispawn : INFO ....... copying '/usr/share/pki/ca/conf/proxy.conf' --> '/etc/pki/pki-tomcat/ca/proxy.conf' with slot substitution
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/ca/proxy.conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/ca/proxy.conf
2019-07-08 03:58:07 pkispawn : INFO ....... ln -s /var/lib/pki/pki-tomcat/alias /var/lib/pki/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown -h 111:117 /var/lib/pki/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : INFO ....... ln -s /etc/pki/pki-tomcat/ca /var/lib/pki/pki-tomcat/ca/conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown -h 111:117 /var/lib/pki/pki-tomcat/ca/conf
2019-07-08 03:58:07 pkispawn : INFO ....... ln -s /var/log/pki/pki-tomcat/ca /var/lib/pki/pki-tomcat/ca/logs
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown -h 111:117 /var/lib/pki/pki-tomcat/ca/logs
2019-07-08 03:58:07 webapp : INFO Creating webapp
2019-07-08 03:58:07 pkispawn : INFO ....... mkdir -p /var/lib/pki/pki-tomcat/ca/webapps
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 770 /var/lib/pki/pki-tomcat/ca/webapps
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /var/lib/pki/pki-tomcat/ca/webapps
2019-07-08 03:58:07 pkispawn : INFO ....... setting ownerships, permissions, and acls on '/var/lib/pki/pki-tomcat/ca/webapps'
2019-07-08 03:58:07 nssdb : INFO Creating NSS database
2019-07-08 03:58:07 pki.server : INFO Loading instance: pki-tomcat
2019-07-08 03:58:07 pki.server : INFO Loading instance registry: /etc/dogtag/tomcat/pki-tomcat/pki-tomcat
2019-07-08 03:58:07 pki.server : INFO Loading subsystem: ca
2019-07-08 03:58:07 pki.server : INFO Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg
2019-07-08 03:58:07 nssdb : INFO Creating password config: /etc/pki/pki-tomcat/password.conf
2019-07-08 03:58:07 nssdb : INFO Creating password file: /etc/pki/pki-tomcat/pfile
2019-07-08 03:58:07 pkispawn : INFO ....... modifying '/etc/pki/pki-tomcat/password.conf'
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /etc/pki/pki-tomcat/password.conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /etc/pki/pki-tomcat/password.conf
2019-07-08 03:58:07 pkispawn : INFO ....... executing 'certutil -N -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/pfile'
2019-07-08 03:58:07 pkispawn : INFO ....... rm -f /etc/pki/pki-tomcat/pfile
2019-07-08 03:58:07 pki.server : INFO Getting signing cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting ocsp_signing cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting sslserver cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting subsystem cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting audit_signing cert info for ca from CS.cfg
2019-07-08 03:58:07 pkispawn : INFO ....... mkdir -p /root/.dogtag/pki-tomcat/ca
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 755 /root/.dogtag/pki-tomcat/ca
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 0:0 /root/.dogtag/pki-tomcat/ca
2019-07-08 03:58:07 nssdb : INFO Creating password file: /root/.dogtag/pki-tomcat/ca/password.conf
2019-07-08 03:58:07 pkispawn : INFO ....... modifying '/root/.dogtag/pki-tomcat/ca/password.conf'
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /root/.dogtag/pki-tomcat/ca/password.conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 0:0 /root/.dogtag/pki-tomcat/ca/password.conf
2019-07-08 03:58:07 pkispawn : INFO ....... generating '/root/.dogtag/pki-tomcat/ca/pkcs12_password.conf'
2019-07-08 03:58:07 pkispawn : INFO ....... modifying '/root/.dogtag/pki-tomcat/ca/pkcs12_password.conf'
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 660 /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 111:117 /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf
2019-07-08 03:58:07 pkispawn : INFO ....... mkdir -p /root/.dogtag/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : DEBUG ........... chmod 770 /root/.dogtag/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : DEBUG ........... chown 0:0 /root/.dogtag/pki-tomcat/ca/alias
2019-07-08 03:58:07 pkispawn : INFO ....... executing 'certutil -N -d /root/.dogtag/pki-tomcat/ca/alias -f /root/.dogtag/pki-tomcat/ca/password.conf'
2019-07-08 03:58:07 selinux : INFO SELinux disabled
2019-07-08 03:58:07 keygen : INFO Generating keys
2019-07-08 03:58:07 pki.server : INFO Loading instance: pki-tomcat
2019-07-08 03:58:07 pki.server : INFO Loading instance registry: /etc/dogtag/tomcat/pki-tomcat/pki-tomcat
2019-07-08 03:58:07 pki.server : INFO Loading password config: /etc/pki/pki-tomcat/password.conf
2019-07-08 03:58:07 pki.server : INFO Loading subsystem: ca
2019-07-08 03:58:07 pki.server : INFO Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting signing cert info for ca from CS.cfg
2019-07-08 03:58:07 pki.server : INFO Getting signing cert info for ca from NSS database
2019-07-08 03:58:07 pki.nssdb : DEBUG Command: certutil -L -d /var/lib/pki/pki-tomcat/alias -f /tmp/tmpQ8ZCeb/password.txt -n caSigningCert cert-pki-ca -a
2019-07-08 03:58:07 keygen : INFO Generating ca_signing CSR in /root/ipa.csr
2019-07-08 03:58:07 pki.nssdb : DEBUG Command: openssl rand -out /tmp/tmpv1RVD7/noise.bin 2048
2019-07-08 03:58:07 pki.nssdb : DEBUG Command: certutil -R -d /var/lib/pki/pki-tomcat/alias -f /tmp/tmpv1RVD7/password.txt -s CN=Certificate Authority,O=EXAMPLE.COM -o /tmp/tmpv1RVD7/request.bin -z /tmp/tmpv1RVD7/noise.bin -k rsa -g 2048 -Z SHA256 --keyUsage certSigning,crlSigning,critical,digitalSignature,nonRepudiation -2
2019-07-08 03:58:07 pkispawn : DEBUG ....... Error Type: CalledProcessError
2019-07-08 03:58:07 pkispawn : DEBUG ....... Error Message: Command '['BtoA', '/tmp/tmpv1RVD7/request.bin', '/tmp/tmpv1RVD7/request.b64']' returned non-zero exit status 1
2019-07-08 03:58:07 pkispawn : DEBUG ....... File "/usr/lib/python2.7/dist-packages/pki/server/pkispawn.py", line 546, in main
scriptlet.spawn(deployer)
File "/usr/lib/python2.7/dist-packages/pki/server/deployment/scriptlets/keygen.py", line 468, in spawn
self.generate_system_cert_requests(deployer, subsystem)
File "/usr/lib/python2.7/dist-packages/pki/server/deployment/scriptlets/keygen.py", line 433, in generate_system_cert_requests
self.generate_ca_signing_csr(deployer, subsystem)
File "/usr/lib/python2.7/dist-packages/pki/server/deployment/scriptlets/keygen.py", line 176, in generate_ca_signing_csr
generic_exts=generic_exts
File "/usr/lib/python2.7/dist-packages/pki/server/deployment/scriptlets/keygen.py", line 113, in generate_csr
generic_exts=generic_exts)
File "/usr/lib/python2.7/dist-packages/pki/nssdb.py", line 613, in create_request
'BtoA', binary_request_file, b64_request_file])
File "/usr/lib/python2.7/subprocess.py", line 190, in check_call
raise CalledProcessError(retcode, cmd)
Do you have the command BtoA and is it in the default path?
This command converts a DER file into base64.
rob
Hi rob I want to install freeipa version 4.7 based on debian9 system, But Debian official apt source only has a part of DEB package, so I install all dependencies through apt-get command, then install these packages manually using dpkg-i command, all configuration is using default configuration, and finally execute ipa-server-install to generate CRT certificate. Books report errors, whether you can give help, or how DEB package compiles. The compilation method on the official website is the way to compile rpm package.
Hi rob I have another question freeipa(4.7.2-3) on debian. Only the list of deb packages:
freeipa-admintools_4.7.2-3_amd64.deb freeipa-common_4.7.2-3_all.deb freeipa-client_4.7.2-3_amd64.deb python-ipaclient_4.7.2-3_all.deb freeipa-client-dbgsym_4.7.2-3_amd64.deb python-ipalib_4.7.2-3_all.deb
why no the deb about freeipa-server? I know the version of 4.7.1 have the deb package. Isn't debian not supporting freeipa-server installation after 4.7.1? Best regard.
On ti, 16 heinä 2019, 1292865949--- via FreeIPA-users wrote:
Hi rob I have another question freeipa(4.7.2-3) on debian. Only the list of deb packages:
freeipa-admintools_4.7.2-3_amd64.deb freeipa-common_4.7.2-3_all.deb freeipa-client_4.7.2-3_amd64.deb python-ipaclient_4.7.2-3_all.deb freeipa-client-dbgsym_4.7.2-3_amd64.deb python-ipalib_4.7.2-3_all.deb
why no the deb about freeipa-server? I know the version of 4.7.1 have the deb package. Isn't debian not supporting freeipa-server installation after 4.7.1?
Yes, Debian does not have full support for IPA server components.
See the following thread for the details: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahoste...
Does the freeipa 4.7.1 version have all the deb packages that support the debian system? Now after installing the pki-ca and pki-kra services, the BtoA command on Ubuntu is normal, but the debian system reports an error with the following error message: root@node1:~# java -version openjdk version "11.0.4-ea" 2019-07-16 OpenJDK Runtime Environment (build 11.0.4-ea+10-post-Debian-1) OpenJDK 64-Bit Server VM (build 11.0.4-ea+10-post-Debian-1, mixed mode, sharing)
root@node1:~# BtoA -Djava.ext.dirs=/usr/share/pki/lib is not supported. Use -classpath instead. Error: Could not create the Java Virtual Machine. Error: A fatal exception has occurred. Program will exit.
On ti, 16 heinä 2019, 1292865949--- via FreeIPA-users wrote:
Does the freeipa 4.7.1 version have all the deb packages that support the debian system? Now after installing the pki-ca and pki-kra services, the BtoA command on Ubuntu is normal, but the debian system reports an error with the following error message:
This is really a question to Debian maintainers. FreeIPA upstream is not involved with packaging on Debian.
I know that Timo Aaltonen is doing a lot of work on making FreeIPA running well on Ubuntu and Debian. He is not always successful because it is a task that needs collaboration from multiple maintainers, not a single one. And people who aren't maintainers cannot really help here other than actually becoming maintainers or submitting patches to the packagers to help them.
So I suggest you to actually report bugs back to Debian bug tracking system, that is the place where a work request should be reported and tracked. If part of a solution would there would be applicable in FreeIPA upstream, we'll be glad to take it in, like we did recently with a number of changes to make Debian use easier in FreeIPA 4.8.0. But only Debian contributors can merge those changes back, where possible.
It is a painful question, surely. I was talking about it at FOSDEM 2019, you might be interested in my talk: https://fosdem.org/2019/schedule/event/freeipa_cross_distrbution_packaging_e...
root@node1:~# java -version openjdk version "11.0.4-ea" 2019-07-16 OpenJDK Runtime Environment (build 11.0.4-ea+10-post-Debian-1) OpenJDK 64-Bit Server VM (build 11.0.4-ea+10-post-Debian-1, mixed mode, sharing)
root@node1:~# BtoA -Djava.ext.dirs=/usr/share/pki/lib is not supported. Use -classpath instead. Error: Could not create the Java Virtual Machine. Error: A fatal exception has occurred. Program will exit. _______________________________________________ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-leave@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahoste...
Hi Alexander At present, we use the source code of the dogtag (10.6.8-2) to be recompiled under jdk8, but the compiled deb package does not match the wrong jar package version. The error message is as follows. I want to know if I can modify the build script to cancel this version check. At the moment we contacted the debian freeipa team and did not get a reply. So take the liberty to find you. Thank you.
root@debian:~/pki/dogtag-pki-10.6.8# dpkg-buildpackage -rfakeroot -uc -b com/netscape/cmsutil/ocsp/OCSPProcessor.java:32: warning: [deprecation] DefaultHttpClient in org.apache.http.impl.client has been deprecated import org.apache.http.impl.client.DefaultHttpClient; ^ com/netscape/cmsutil/password/NuxwdogPasswordStore.java:15: error: cannot access WatchdogClient import com.redhat.nuxwdog.WatchdogClient; ^ bad class file: /usr/share/java/nuxwdog.jar(com/redhat/nuxwdog/WatchdogClient.class) class file has wrong version 55.0, should be 52.0 Please remove or make sure it appears in the correct subdirectory of the classpath. make[4]: *** [base/util/src/CMakeFiles/pki-cmsutil-classes.dir/build.make:62: pki-cmsutil-classes] Error 1 make[4]: Leaving directory '/root/pki/dogtag-pki-10.6.8/build/core' make[3]: *** [CMakeFiles/Makefile2:628: base/util/src/CMakeFiles/pki-cmsutil-classes.dir/all] Error 2 make[3]: Leaving directory '/root/pki/dogtag-pki-10.6.8/build/core' make[2]: *** [Makefile:152: all] Error 2 make[2]: Leaving directory '/root/pki/dogtag-pki-10.6.8/build/core' make[1]: *** [debian/rules:63: debian/stamp/x86_64-linux-gnu-build-core] Error 2 make[1]: Leaving directory '/root/pki/dogtag-pki-10.6.8' make: *** [debian/rules:48: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 root@debian:~/pki/dogtag-pki-10.6.8# root@debian:~/pki/dogtag-pki-10.6.8#
Hi rob
Our system have the command. But it doesn't work well. The error log belows. Debian10 installed pki and jdk above is have this bug? We replaced the jdk version into 11.0.3, the problem still exists. How to debug the question?
root@node1:~# BtoA
-Djava.ext.dirs=/usr/share/pki/lib is not supported. Use -classpath instead.
Error: Could not create the Java Virtual Machine.
Error: A fatal exception has occurred. Program will exit.
The system info belows:
root@node1:~# uname -r
4.19.0-5-amd64
root@node1:~#
root@node1:~# java -version
openjdk version "11.0.4-ea" 2019-07-16
OpenJDK Runtime Environment (build 11.0.4-ea+10-post-Debian-1)
OpenJDK 64-Bit Server VM (build 11.0.4-ea+10-post-Debian-1, mixed mode, sharing)
root@node1:~#
root@node1:~#
root@node1:~# dpg -l pki*
-bash: dpg: command not found
root@node1:~#
root@node1:~#
root@node1:~# dpkg -l pki*
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name Version Architecture Description
+++-==============-============-============-=========================================================
ii pki-base 10.6.8-2 all Certificate System - PKI Framework
ii pki-base-java 10.6.8-2 all Certificate System - PKI Framework -- java client support
ii pki-ca 10.6.8-2 all Certificate System - Certificate Authority
ii pki-kra 10.6.8-2 all Certificate System - Data Recovery Manager
ii pki-server 10.6.8-2 amd64 Certificate System - PKI Server Framework
ii pki-tools 10.6.8-2 amd64 Certificate System - PKI Tools
On 12.7.2019 11.20, 1292865949--- via FreeIPA-users wrote:
hello all:
I am trying to install the freeipa-server(4.7.1) package on Debian9, which is
now failing, the failed message is pkispawn failed. The installation output is as follows, after running apt install
freeipa-server. I want to know the effective way of installation freeipa-server
on debian. Can you provide the way of compile the freeipa project?
- Debian9 system info.
Linux root 4.9.0-9-amd64 #1 SMP Debian 4.9.168-1 (2019-04-12) x86_64 GNU/Linux
Hi,
Sorry, only Debian unstable is somewhat supported right now, though the freeipa part is still lacking because of ipa-server-upgrade crashes I'm seeing which is blocking the upload of current version being staged. I'll probably rebase to 4.8.0 starting next month and move it all to python3 now that the Samba packages support it...
anyway, Dogtag absolutely needs JDK8 or it'll break horribly, don't even try with JDK11.
Hi Timo,
On 7/19/19 8:51 AM, Timo Aaltonen via FreeIPA-users wrote:
Hi,
Sorry, only Debian unstable is somewhat supported right now, though the freeipa part is still lacking because of ipa-server-upgrade crashes I'm seeing which is blocking the upload of current version being staged. I'll probably rebase to 4.8.0 starting next month and move it all to python3 now that the Samba packages support it...
don't worry, this thread is about freeipa-server on CentOS 7 in a LXC container. Debian is the host.
My Debian clients work very well using your freeipa-client package.
Regards Harri
Please ignore, I got confused with another thread. Harri
On 7/19/19 10:22 AM, Harald Dunkel wrote:
Hi Timo,
On 7/19/19 8:51 AM, Timo Aaltonen via FreeIPA-users wrote:
Hi,
Sorry, only Debian unstable is somewhat supported right now, though the freeipa part is still lacking because of ipa-server-upgrade crashes I'm seeing which is blocking the upload of current version being staged. I'll probably rebase to 4.8.0 starting next month and move it all to python3 now that the Samba packages support it...
don't worry, this thread is about freeipa-server on CentOS 7 in a LXC container. Debian is the host.
My Debian clients work very well using your freeipa-client package.
Regards Harri
freeipa-users@lists.fedorahosted.org