hello, Am Freitag, 17. Juni 2016, 23:05:32 CEST schrieb Martin Basti: > On 17.06.2016 18:29, Günther J. Niederwimmer wrote: > > Hello, > > > > Am Freitag, 17. Juni 2016, 14:13:55 CEST schrieb Martin Basti: > >> On 17.06.2016 12:54, Günther J. Niederwimmer wrote: > >>> Hello List, > >>> > >>> Am Freitag, 17. Juni 2016, 07:51:45 CEST schrieb Petr Spacek: > >>>> On 16.6.2016 21:51, Lukas Slebodnik wrote: > >>>>> On (16/06/16 11:54), Günther J. Niederwimmer wrote: > >>>>>> Hello > >>>>>> > >>>>>> on my system the ods-exporter i mean have a problem. > >>>>>> > >>>>>> I have this in the logs > >>>>>> CentOS 7.(2) ipa 4.3.1 > >>>>>> > >>>>>> Jun 16 11:38:28 ipa ipa-ods-exporter: raise > >>>>>> errors.ACIError(info=info) > >>>>>> Jun 16 11:38:28 ipa ipa-ods-exporter: ipalib.errors.ACIError: > >>>>>> Insufficient > >>>>>> access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS > >>>>>> failure. > >>>>>> Minor code may provide more information (Ticket expired) > >>>>>> > >>>>> ^^^^^^^^^^^^^^ > >>>>> > >>>>> Here seems to be a reason why it failed. > >>>>> But I can't help you more. > >>>> > >>>> Lukas is right. Interesting, this should never happen :-) > >>> > >>> this have I also found ;-) > >>> > >>>> Please enable debugging using procedure > >>>> http://www.freeipa.org/page/Troubleshooting#ipa_command_crashes_or_retu > >>>> rn > >>>> s_n o_data and check logs after next ipa-ods-exporter restart. > >>>> Thank you! > >>> > >>> OK, > >>> > >>> I attache the messages log? > >>> > >>> I mean this is a problem with my DNS ? > >> > >> Hello, > >> can you check kerberos status of ipa-ods-exporter service in webUI? > >> > >> identity/services/ipa-ods-exported/<hostname> > >> There should be kerberos status in right top corner in details view > > > > I have a > > identity/services/ipa-ods-exporter/.. > > > > with a "Kerberos Key Present, Service Provisioned" > > > > but no Certificate ? > > Can you try, > > # kinit -kt /etc/ipa/dnssec/ipa-ods-exporter.keytab > ipa-ods-exporter/$(hostname)
OK I can do a "kinit -kt /etc/ipa/dnssec/ipa-ods-exporter.keytab ipa-ods- exporter/$(hostname)" written on one line!! is this OK. > and do ldapsearch > # ldapsearch -Y GSSAPI and also ldapsearch is OK > It should show us if keytab is okay But the Error is present :-(. > Certificate is not needed. OK Thanks for the Help. -- mit freundlichen Grüßen / best regards, Günther J. Niederwimmer -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project
