On 12/06/2012 12:44 PM, Maciej Sawicki wrote: > On Thu, Dec 6, 2012 at 5:57 PM, John Dennis <[email protected]> wrote: >> Yes, that's right, reboot twice! (Apparently that's needed to get systemd >> updates installed and working) >> > unfortunately it didn't help. > > the strange thing is that during first try (remove freeipa-server > packege, reboot, reboot, install free-ipaserver, reboot, reboot, run > ipa-server-install) i get one more error: > > > Configuring directory server for the CA (pkids): Estimated time 30 seconds > [1/3]: creating directory server user > [2/3]: creating directory server instance > ipa : CRITICAL failed to create ds instance Command > '/usr/sbin/setup-ds.pl --silent --logfile - -f /tmp/tmpWS7pd0' > returned non-zero exit status 1 > [3/3]: restarting directory server > ipa : CRITICAL Failed to restart the directory server. See the > installation log for details. > Done configuring directory server for the CA (pkids). > Configuring certificate server (pki-tomcatd): Estimated time 3 minutes > 30 seconds > [1/19]: creating certificate server user > [2/19]: configuring certificate server instance > ipa : CRITICAL failed to configure ca instance Command > '/usr/sbin/pkispawn -s CA -f /tmp/tmpTf7vHu' returned non-zero exit > status 1 > > and log: > > ############################################################################### > ## 'TPS' Data: > ## > ## > ## > ## Values in this section are common to PKI TPS subsystems, and contain > ## > ## required information which MAY be overridden by users as necessary. > ## > ############################################################################### > [TPS] > pki_subsystem=TPS > pki_subsystem_name= > > 2012-12-06T17:40:27Z DEBUG Starting external process > 2012-12-06T17:40:27Z DEBUG args=/usr/sbin/pkispawn -s CA -f /tmp/tmpTf7vHu > 2012-12-06T17:40:31Z DEBUG Process finished, return code=1 > 2012-12-06T17:40:31Z DEBUG stdout= > 2012-12-06T17:40:31Z DEBUG stderr=Traceback (most recent call last): > File "/usr/sbin/pkispawn", line 223, in <module> > main(sys.argv) > File "/usr/sbin/pkispawn", line 207, in main > fromlist = [pki_scriptlet[4:]]) > File "/usr/lib/python2.7/site-packages/pki/deployment/initialization.py", > line 25, in <module> > import pkihelper as util > File "/usr/lib/python2.7/site-packages/pki/deployment/pkihelper.py", > line 39, in <module> > import seobject > File "/usr/lib64/python2.7/site-packages/seobject.py", line 27, in <module> > import sepolicy > File "/usr/lib64/python2.7/site-packages/sepolicy/__init__.py", line > 43, in <module> > policy(policy_file) > File "/usr/lib64/python2.7/site-packages/sepolicy/__init__.py", line > 40, in policy > _policy.policy(policy_file) > RuntimeError: Cannot allocate memory > > 2012-12-06T17:40:31Z CRITICAL failed to configure ca instance Command > '/usr/sbin/pkispawn -s CA -f /tmp/tmpTf7vHu' returned non-zero exit > status 1 > 2012-12-06T17:40:31Z INFO File > "/usr/lib/python2.7/site-packages/ipaserver/install/installutils.py", > line 614, in run_script > return_value = main_function() > > File "/sbin/ipa-server-install", line 943, in main > subject_base=options.subject) > > File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", > line 591, in configure_instance > self.start_creation(runtime=210) > > File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", > line 358, in start_creation > method() > > File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", > line 695, in __spawn_instance > raise RuntimeError('Configuration of CA failed') > > 2012-12-06T17:40:31Z INFO The ipa-server-install command failed, > exception: RuntimeError: Configuration of CA failed > > but after: ipa-server-install --uninstall, ipa-server-install i get > only second error: > [2/19]: configuring certificate server instance > ipa : CRITICAL failed to configure ca instance Command > '/usr/sbin/pkispawn -s CA -f /tmp/tmpTf7vHu' returned non-zero exit > status 1 > > regards, > Maciek Sawicki > > _______________________________________________ > Freeipa-users mailing list > [email protected] > https://www.redhat.com/mailman/listinfo/freeipa-users Do you have SELinux enabled? Any AVCs?
-- Thank you, Dmitri Pal Sr. Engineering Manager for IdM portfolio Red Hat Inc. ------------------------------- Looking to carve out IT costs? www.redhat.com/carveoutcosts/ _______________________________________________ Freeipa-users mailing list [email protected] https://www.redhat.com/mailman/listinfo/freeipa-users
