ipa replica does not configure ntp service When ipa-replica-install runs with NTP option (-N, --ntp-server= --ntp-server=, --ntp-pool=)
-ipa-replica should configure ntp service using 1.pool.ntp.org NTP server -1.pool.ntp.org should added in /etc/chrony.conf
cat /etc/redhat-release Fedora release 28 (Twenty Eight) rpm -q freeipa-server freeipa-client ipa-server ipa-client 389-ds-base pki-ca krb5-server freeipa-server-4.7.0-3.fc28.x86_64 freeipa-client-4.7.0-3.fc28.x86_64 package ipa-server is not installed package ipa-client is not installed 389-ds-base-1.4.0.16-1.fc28.x86_64 pki-ca-10.6.6-1.fc28.noarch krb5-server-1.16.1-13.fc28.x86_64
Console output:-
[root@ivanova ~]# ipa-replica-install --principal admin --admin-password Secret123 --server mgmt9.rhq.lab.eng.bos.redhat.com --domain rhq.lab.eng.bos.redhat.com --ntp-server=1.pool.ntp.org Configuring client side components This program will set up FreeIPA client. Version 4.7.0
Using existing certificate '/etc/ipa/ca.crt'. Client hostname: ivanova.idmqe.lab.eng.bos.redhat.com Realm: RHQ.LAB.ENG.BOS.REDHAT.COM DNS Domain: rhq.lab.eng.bos.redhat.com IPA Server: mgmt9.rhq.lab.eng.bos.redhat.com BaseDN: dc=rhq,dc=lab,dc=eng,dc=bos,dc=redhat,dc=com
Synchronizing time No SRV records of NTP servers found and no NTP server or pool address was provided. Using default chrony configuration. Attempting to sync time with chronyc. Time synchronization was successful. Enrolled in IPA realm RHQ.LAB.ENG.BOS.REDHAT.COM Created /etc/ipa/default.conf Configured sudoers in /etc/nsswitch.conf Configured /etc/sssd/sssd.conf Configured /etc/krb5.conf for IPA realm RHQ.LAB.ENG.BOS.REDHAT.COM Systemwide CA database updated. Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub Could not update DNS SSHFP records. WARNING: The configuration pre-client installation is not managed by authselect and cannot be backed up. Uninstallation may not be able to revert to the original state. SSSD enabled Configured /etc/openldap/ldap.conf Configured /etc/ssh/ssh_config Configured /etc/ssh/sshd_config Configuring rhq.lab.eng.bos.redhat.com as NIS domain. Client configuration complete. The ipa-client-install command was successful
Run connection check to master Connection check OK Configuring directory server (dirsrv). Estimated time: 30 seconds [1/41]: creating directory server instance [2/41]: enabling ldapi [3/41]: configure autobind for root [4/41]: stopping directory server [5/41]: updating configuration in dse.ldif [6/41]: starting directory server [7/41]: adding default schema [8/41]: enabling memberof plugin [9/41]: enabling winsync plugin [10/41]: configuring replication version plugin [11/41]: enabling IPA enrollment plugin [12/41]: configuring uniqueness plugin [13/41]: configuring uuid plugin [14/41]: configuring modrdn plugin [15/41]: configuring DNS plugin [16/41]: enabling entryUSN plugin [17/41]: configuring lockout plugin [18/41]: configuring topology plugin [19/41]: creating indices [20/41]: enabling referential integrity plugin [21/41]: configuring certmap.conf [22/41]: configure new location for managed entries [23/41]: configure dirsrv ccache [24/41]: enabling SASL mapping fallback [25/41]: restarting directory server [26/41]: creating DS keytab [27/41]: ignore time skew for initial replication [28/41]: setting up initial replication Starting replication, please wait until this has completed. Update in progress, 7 seconds elapsed Update succeeded
[29/41]: prevent time skew after initial replication [30/41]: adding sasl mappings to the directory [31/41]: updating schema [32/41]: setting Auto Member configuration [33/41]: enabling S4U2Proxy delegation [34/41]: initializing group membership [35/41]: adding master entry [36/41]: initializing domain level [37/41]: configuring Posix uid/gid generation [38/41]: adding replication acis [39/41]: activating sidgen plugin [40/41]: activating extdom plugin [41/41]: configuring directory to start on boot Done configuring directory server (dirsrv). Configuring Kerberos KDC (krb5kdc) [1/5]: configuring KDC [2/5]: adding the password extension to the directory [3/5]: creating anonymous principal [4/5]: starting the KDC [5/5]: configuring KDC to start on boot Done configuring Kerberos KDC (krb5kdc). Configuring kadmin [1/2]: starting kadmin [2/2]: configuring kadmin to start on boot Done configuring kadmin. Configuring directory server (dirsrv) [1/3]: configuring TLS for DS instance [2/3]: importing CA certificates from LDAP [3/3]: restarting directory server Done configuring directory server (dirsrv). Configuring the web interface (httpd) [1/21]: stopping httpd [2/21]: backing up ssl.conf [3/21]: disabling nss.conf [4/21]: configuring mod_ssl certificate paths [5/21]: setting mod_ssl protocol list to TLSv1.0 - TLSv1.2 [6/21]: configuring mod_ssl log directory [7/21]: disabling mod_ssl OCSP [8/21]: adding URL rewriting rules [9/21]: configuring httpd [10/21]: setting up httpd keytab [11/21]: configuring Gssproxy [12/21]: setting up ssl [13/21]: configure certmonger for renewals [14/21]: publish CA cert [15/21]: clean up any existing httpd ccaches [16/21]: configuring SELinux for httpd [17/21]: create KDC proxy config [18/21]: enable KDC proxy [19/21]: starting httpd [20/21]: configuring httpd to start on boot [21/21]: enabling oddjobd Done configuring the web interface (httpd). Configuring ipa-otpd [1/2]: starting ipa-otpd [2/2]: configuring ipa-otpd to start on boot Done configuring ipa-otpd. Configuring ipa-custodia [1/4]: Generating ipa-custodia config file [2/4]: Generating ipa-custodia keys [3/4]: starting ipa-custodia [4/4]: configuring ipa-custodia to start on boot Done configuring ipa-custodia. Configuring certificate server (pki-tomcatd) [1/2]: configure certmonger for renewals [2/2]: Importing RA key Done configuring certificate server (pki-tomcatd). Configuring Kerberos KDC (krb5kdc) [1/1]: installing X509 Certificate for PKINIT Full PKINIT configuration did not succeed The setup will only install bits essential to the server functionality You can enable PKINIT after the setup completed using 'ipa-pkinit-manage' Done configuring Kerberos KDC (krb5kdc). Applying LDAP updates Upgrading IPA:. Estimated time: 1 minute 30 seconds [1/10]: stopping directory server [2/10]: saving configuration [3/10]: disabling listeners [4/10]: enabling DS global lock [5/10]: disabling Schema Compat [6/10]: starting directory server [7/10]: upgrading server [8/10]: stopping directory server [9/10]: restoring configuration [10/10]: starting directory server Done. Finalize replication settings Restarting the KDC
WARNING: The CA service is only installed on one server (mgmt9.rhq.lab.eng.bos.redhat.com). It is strongly recommended to install it on another server. Run ipa-ca-install(1) on another master to accomplish this.
[root@ivanova ~]# cat /etc/chrony.conf -# These servers were defined in the installation: -# Use public servers from the pool.ntp.org project. -# Please consider joining the pool (http://www.pool.ntp.org/join.html).
-# Record the rate at which the system clock gains/losses time. driftfile /var/lib/chrony/drift
-# Allow the system clock to be stepped in the first three updates -# if its offset is larger than 1 second. makestep 1.0 3
-# Enable kernel synchronization of the real-time clock (RTC). rtcsync
-# Enable hardware timestamping on all interfaces that support it. -#hwtimestamp *
-# Increase the minimum number of selectable sources required to adjust -# the system clock. -#minsources 2
-# Allow NTP client access from local network. -#allow 192.168.0.0/16
-# Serve time even if not synchronized to a time source. -#local stratum 10
-# Specify file containing keys for NTP authentication. keyfile /etc/chrony.keys
-# Get TAI-UTC offset and leap seconds from the system tz database. leapsectz right/UTC
-# Specify directory for log files. logdir /var/log/chrony
-# Select which information is logged. -#log measurements statistics tracking
-###################################################################
[root@cypher ~]# ipa-client-install --server mgmt9.rhq.lab.eng.bos.redhat.com --domain rhq.lab.eng.bos.redhat.com This program will set up FreeIPA client. Version 4.7.0
Autodiscovery of servers for failover cannot work with this configuration. If you proceed with the installation, services will be configured to always access the discovered server for all operations and will not fail over to other servers in case of failure. Proceed with fixed values and no DNS discovery? [no]: yes Client hostname: cypher.idmqe.lab.eng.bos.redhat.com Realm: RHQ.LAB.ENG.BOS.REDHAT.COM DNS Domain: rhq.lab.eng.bos.redhat.com IPA Server: mgmt9.rhq.lab.eng.bos.redhat.com BaseDN: dc=rhq,dc=lab,dc=eng,dc=bos,dc=redhat,dc=com
Continue to configure the system with these values? [no]: yes Synchronizing time No SRV records of NTP servers found and no NTP server or pool address was provided. Using default chrony configuration. Attempting to sync time with chronyc. Time synchronization was successful. User authorized to enroll computers: admin Password for admin@RHQ.LAB.ENG.BOS.REDHAT.COM: Successfully retrieved CA cert Subject: CN=Certificate Authority,O=RHQ.LAB.ENG.BOS.REDHAT.COM Issuer: CN=Certificate Authority,O=RHQ.LAB.ENG.BOS.REDHAT.COM Valid From: 2018-10-03 14:49:45 Valid Until: 2038-10-03 14:49:45
Enrolled in IPA realm RHQ.LAB.ENG.BOS.REDHAT.COM Created /etc/ipa/default.conf Configured sudoers in /etc/nsswitch.conf Configured /etc/sssd/sssd.conf Configured /etc/krb5.conf for IPA realm RHQ.LAB.ENG.BOS.REDHAT.COM Systemwide CA database updated. Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub Could not update DNS SSHFP records. WARNING: The configuration pre-client installation is not managed by authselect and cannot be backed up. Uninstallation may not be able to revert to the original state. SSSD enabled Configured /etc/openldap/ldap.conf Configured /etc/ssh/ssh_config Configured /etc/ssh/sshd_config Configuring rhq.lab.eng.bos.redhat.com as NIS domain. Client configuration complete. The ipa-client-install command was successful
[root@cypher ~]# ipa-replica-install --ntp-server=1.pool.ntp.org Password for admin@RHQ.LAB.ENG.BOS.REDHAT.COM: Run connection check to master Connection check OK Configuring directory server (dirsrv). Estimated time: 30 seconds [1/41]: creating directory server instance [2/41]: enabling ldapi [3/41]: configure autobind for root [4/41]: stopping directory server [5/41]: updating configuration in dse.ldif [6/41]: starting directory server [7/41]: adding default schema [8/41]: enabling memberof plugin [9/41]: enabling winsync plugin [10/41]: configuring replication version plugin [11/41]: enabling IPA enrollment plugin [12/41]: configuring uniqueness plugin [13/41]: configuring uuid plugin [14/41]: configuring modrdn plugin [15/41]: configuring DNS plugin [16/41]: enabling entryUSN plugin [17/41]: configuring lockout plugin [18/41]: configuring topology plugin [19/41]: creating indices [20/41]: enabling referential integrity plugin [21/41]: configuring certmap.conf [22/41]: configure new location for managed entries [23/41]: configure dirsrv ccache [24/41]: enabling SASL mapping fallback [25/41]: restarting directory server [26/41]: creating DS keytab [27/41]: ignore time skew for initial replication [28/41]: setting up initial replication Starting replication, please wait until this has completed. Update in progress, 8 seconds elapsed Update succeeded
[root@cypher ~]# cat /etc/chrony.conf -# These servers were defined in the installation: -# Use public servers from the pool.ntp.org project. -# Please consider joining the pool (http://www.pool.ntp.org/join.html).
-# Select which information is logged. -#log measurements statistics tracking [root@cypher ~]#
[root@mgmt9 ~]# ipa-server-install --ntp-server=1.pool.ntp.org
This program will set up the FreeIPA Server. Version 4.7.0
This includes: * Configure a stand-alone CA (dogtag) for certificate management * Configure the NTP client (chronyd) * Create and configure an instance of Directory Server * Create and configure a Kerberos Key Distribution Center (KDC) * Configure Apache (httpd) * Configure the KDC to enable PKINIT
To accept the default shown in brackets, press the Enter key.
Do you want to configure integrated DNS (BIND)? [no]:
Enter the fully qualified domain name of the computer on which you're setting up server software. Using the form . Example: master.example.com.
Server host name [mgmt9.rhq.lab.eng.bos.redhat.com]:
The domain name has been determined based on the host name.
Please confirm the domain name [rhq.lab.eng.bos.redhat.com]:
The kerberos protocol requires a Realm name to be defined. This is typically the domain name converted to uppercase.
Please provide a realm name [RHQ.LAB.ENG.BOS.REDHAT.COM]: Certain directory server operations require an administrative user. This user is referred to as the Directory Manager and has full access to the Directory for system management tasks and will be added to the instance of directory server created for IPA. The password must be at least 8 characters long.
Directory Manager password: Password (confirm):
The IPA server requires an administrative user, named 'admin'. This user is a regular system account used for IPA server administration.
IPA admin password: Password (confirm):
The IPA Master Server will be configured with: Hostname: mgmt9.rhq.lab.eng.bos.redhat.com IP address(es): 10.16.4.19 Domain name: rhq.lab.eng.bos.redhat.com Realm name: RHQ.LAB.ENG.BOS.REDHAT.COM
The CA will be configured with: Subject DN: CN=Certificate Authority,O=RHQ.LAB.ENG.BOS.REDHAT.COM Subject base: O=RHQ.LAB.ENG.BOS.REDHAT.COM Chaining: self-signed
Continue to configure the system with these values? [no]: yes
The following operations may take some minutes to complete. Please wait until the prompt is returned.
Synchronizing time Configuration of chrony was changed by installer. Attempting to sync time with chronyc. Time synchronization was successful. Configuring directory server (dirsrv). Estimated time: 30 seconds [1/44]: creating directory server instance [2/44]: enabling ldapi [3/44]: configure autobind for root * * * * Please add records in this file to your DNS system: /tmp/ipa.system.records.af3cbvc7.db ============================================================================== Setup complete * * The ipa-server-install command was successful
[root@mgmt9 ~]# cat /etc/chrony.conf -# These servers were defined in the installation: -# Use public servers from the pool.ntp.org project. -# Please consider joining the pool (http://www.pool.ntp.org/join.html).
-# Select which information is logged. -#log measurements statistics tracking server 1.pool.ntp.org iburst
The client installer handles the NTP server/pool configuration.
There are two separate issues:
Metadata Update from @rcritten: - Issue assigned to rcritten
https://github.com/freeipa/freeipa/pull/2451
Metadata Update from @rcritten: - Issue priority set to: normal - Issue set to the milestone: FreeIPA 4.7.2
For the first case we can pass the NTP options down to the client installer.
For the second case (pre-enrolled) we will raise an exception. There are a bunch of corner cases and it is just far easier to uninstall and re-install the client to change the NTP config (or do manual changes).
master:
ipa-4-7:
Metadata Update from @rcritten: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
Metadata Update from @rcritten: - Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1651679
Issue linked to Bugzilla: Bug 1651679