FYI: I was digging a little more and it seems that there could be some
issue with GSSAPI authentication in kerberos.
Michal
On 27. 09. 23 12:45, Alexander Bokovoy wrote:
On Срд, 27 вер 2023, Michal Konecny wrote:
> Hi,
>
> the VM I'm using is completely new, it could be something in our
> ansible playbook that I'm using to deploy it. The playbook is here:
>
https://pagure.io/fedora-infra/ansible/blob/main/f/playbooks/groups/ipa.yml,
> but it is created for RHEL-8, so it fails on setting up KRA.
>
> Where should I fill the issue?
Please use
https://pagure.io/freeipa/issues
>
> Michal
>
> On 27. 09. 23 10:24, Alexander Bokovoy wrote:
>> On Срд, 27 вер 2023, Michal Konecny via FreeIPA-users wrote:
>>> Hi everyone,
>>>
>>> I'm currently trying to update Fedora IPA installation on staging
>>> from RHEL 8 to RHEL 9. I'm using this guide
>>>
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/...
>>> for it.
>>>
>>> I'm currently stuck on error "RuntimeError: Failed to start
>>> replication" and I don't see anything strange in the logs. Here is
>>> the log from `ipa-replica-install` run:
>>>
https://paste.centos.org/view/a0e2c2b9 . Maybe somebody here will
>>> know what seems to be the problem.
>>
>> The only odd thing I can see is a bit of discrepancy between
>> handling of
>> JSON structure in check_repl_init() and check_repl_update(). We fail
>> due
>> to the former not expecting 'Error (0) No replication sessions started
>> since server startup' status message.
>>
>> I think the replication actually succeeded in one of previous DS
>> restarts, that's why we've got here.
>>
>> Please create an issue and attach this pastebin content there.
>>
>