#7723 NTP options fails on ipa replica
Closed: fixed Opened by mvarun.

Issue

ipa replica does not configure ntp service When ipa-replica-install runs with NTP option (-N, --ntp-server= --ntp-server=, --ntp-pool=)

Steps to Reproduce

  1. Setup ipa-server
  2. install ipa-replica with option --ntp-server=
    • ipa-replica-install --principal admin --admin-password --ntp-server=1.pool.ntp.org
      or
    • ipa-client-install
    • ipa-replica-install --ntp-server=1.pool.ntp.org

Actual behavior

  • ipa-replica not configure ntp service using NTP server(1.pool.ntp.org)
  • 1.pool.ntp.org not added in /etc/chrony.conf

Expected behavior

-ipa-replica should configure ntp service using 1.pool.ntp.org NTP server
-1.pool.ntp.org should added in /etc/chrony.conf

Version/Release/Distribution

cat /etc/redhat-release
Fedora release 28 (Twenty Eight)
rpm -q freeipa-server freeipa-client ipa-server ipa-client 389-ds-base pki-ca krb5-server
freeipa-server-4.7.0-3.fc28.x86_64
freeipa-client-4.7.0-3.fc28.x86_64
package ipa-server is not installed
package ipa-client is not installed
389-ds-base-1.4.0.16-1.fc28.x86_64
pki-ca-10.6.6-1.fc28.noarch
krb5-server-1.16.1-13.fc28.x86_64

Additional info:

Console output:-

1) Replica installed on a machine that has not yet been enrolled in the IdM domain

[root@ivanova ~]# ipa-replica-install --principal admin --admin-password Secret123 --server mgmt9.rhq.lab.eng.bos.redhat.com --domain rhq.lab.eng.bos.redhat.com --ntp-server=1.pool.ntp.org
Configuring client side components
This program will set up FreeIPA client.
Version 4.7.0

Using existing certificate '/etc/ipa/ca.crt'.
Client hostname: ivanova.idmqe.lab.eng.bos.redhat.com
Realm: RHQ.LAB.ENG.BOS.REDHAT.COM
DNS Domain: rhq.lab.eng.bos.redhat.com
IPA Server: mgmt9.rhq.lab.eng.bos.redhat.com
BaseDN: dc=rhq,dc=lab,dc=eng,dc=bos,dc=redhat,dc=com

Synchronizing time
No SRV records of NTP servers found and no NTP server or pool address was provided.
Using default chrony configuration.
Attempting to sync time with chronyc.
Time synchronization was successful.
Enrolled in IPA realm RHQ.LAB.ENG.BOS.REDHAT.COM
Created /etc/ipa/default.conf
Configured sudoers in /etc/nsswitch.conf
Configured /etc/sssd/sssd.conf
Configured /etc/krb5.conf for IPA realm RHQ.LAB.ENG.BOS.REDHAT.COM
Systemwide CA database updated.
Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub
Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub
Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub
Could not update DNS SSHFP records.
WARNING: The configuration pre-client installation is not managed by authselect and cannot be backed up. Uninstallation may not be able to revert to the original state.
SSSD enabled
Configured /etc/openldap/ldap.conf
Configured /etc/ssh/ssh_config
Configured /etc/ssh/sshd_config
Configuring rhq.lab.eng.bos.redhat.com as NIS domain.
Client configuration complete.
The ipa-client-install command was successful

Run connection check to master
Connection check OK
Configuring directory server (dirsrv). Estimated time: 30 seconds
[1/41]: creating directory server instance
[2/41]: enabling ldapi
[3/41]: configure autobind for root
[4/41]: stopping directory server
[5/41]: updating configuration in dse.ldif
[6/41]: starting directory server
[7/41]: adding default schema
[8/41]: enabling memberof plugin
[9/41]: enabling winsync plugin
[10/41]: configuring replication version plugin
[11/41]: enabling IPA enrollment plugin
[12/41]: configuring uniqueness plugin
[13/41]: configuring uuid plugin
[14/41]: configuring modrdn plugin
[15/41]: configuring DNS plugin
[16/41]: enabling entryUSN plugin
[17/41]: configuring lockout plugin
[18/41]: configuring topology plugin
[19/41]: creating indices
[20/41]: enabling referential integrity plugin
[21/41]: configuring certmap.conf
[22/41]: configure new location for managed entries
[23/41]: configure dirsrv ccache
[24/41]: enabling SASL mapping fallback
[25/41]: restarting directory server
[26/41]: creating DS keytab
[27/41]: ignore time skew for initial replication
[28/41]: setting up initial replication
Starting replication, please wait until this has completed.
Update in progress, 7 seconds elapsed
Update succeeded

[29/41]: prevent time skew after initial replication
[30/41]: adding sasl mappings to the directory
[31/41]: updating schema
[32/41]: setting Auto Member configuration
[33/41]: enabling S4U2Proxy delegation
[34/41]: initializing group membership
[35/41]: adding master entry
[36/41]: initializing domain level
[37/41]: configuring Posix uid/gid generation
[38/41]: adding replication acis
[39/41]: activating sidgen plugin
[40/41]: activating extdom plugin
[41/41]: configuring directory to start on boot
Done configuring directory server (dirsrv).
Configuring Kerberos KDC (krb5kdc)
[1/5]: configuring KDC
[2/5]: adding the password extension to the directory
[3/5]: creating anonymous principal
[4/5]: starting the KDC
[5/5]: configuring KDC to start on boot
Done configuring Kerberos KDC (krb5kdc).
Configuring kadmin
[1/2]: starting kadmin
[2/2]: configuring kadmin to start on boot
Done configuring kadmin.
Configuring directory server (dirsrv)
[1/3]: configuring TLS for DS instance
[2/3]: importing CA certificates from LDAP
[3/3]: restarting directory server
Done configuring directory server (dirsrv).
Configuring the web interface (httpd)
[1/21]: stopping httpd
[2/21]: backing up ssl.conf
[3/21]: disabling nss.conf
[4/21]: configuring mod_ssl certificate paths
[5/21]: setting mod_ssl protocol list to TLSv1.0 - TLSv1.2
[6/21]: configuring mod_ssl log directory
[7/21]: disabling mod_ssl OCSP
[8/21]: adding URL rewriting rules
[9/21]: configuring httpd
[10/21]: setting up httpd keytab
[11/21]: configuring Gssproxy
[12/21]: setting up ssl
[13/21]: configure certmonger for renewals
[14/21]: publish CA cert
[15/21]: clean up any existing httpd ccaches
[16/21]: configuring SELinux for httpd
[17/21]: create KDC proxy config
[18/21]: enable KDC proxy
[19/21]: starting httpd
[20/21]: configuring httpd to start on boot
[21/21]: enabling oddjobd
Done configuring the web interface (httpd).
Configuring ipa-otpd
[1/2]: starting ipa-otpd
[2/2]: configuring ipa-otpd to start on boot
Done configuring ipa-otpd.
Configuring ipa-custodia
[1/4]: Generating ipa-custodia config file
[2/4]: Generating ipa-custodia keys
[3/4]: starting ipa-custodia
[4/4]: configuring ipa-custodia to start on boot
Done configuring ipa-custodia.
Configuring certificate server (pki-tomcatd)
[1/2]: configure certmonger for renewals
[2/2]: Importing RA key
Done configuring certificate server (pki-tomcatd).
Configuring Kerberos KDC (krb5kdc)
[1/1]: installing X509 Certificate for PKINIT
Full PKINIT configuration did not succeed
The setup will only install bits essential to the server functionality
You can enable PKINIT after the setup completed using 'ipa-pkinit-manage'
Done configuring Kerberos KDC (krb5kdc).
Applying LDAP updates
Upgrading IPA:. Estimated time: 1 minute 30 seconds
[1/10]: stopping directory server
[2/10]: saving configuration
[3/10]: disabling listeners
[4/10]: enabling DS global lock
[5/10]: disabling Schema Compat
[6/10]: starting directory server
[7/10]: upgrading server
[8/10]: stopping directory server
[9/10]: restoring configuration
[10/10]: starting directory server
Done.
Finalize replication settings
Restarting the KDC

WARNING: The CA service is only installed on one server (mgmt9.rhq.lab.eng.bos.redhat.com).
It is strongly recommended to install it on another server.
Run ipa-ca-install(1) on another master to accomplish this.

[root@ivanova ~]# cat /etc/chrony.conf
-# These servers were defined in the installation:
-# Use public servers from the pool.ntp.org project.
-# Please consider joining the pool (http://www.pool.ntp.org/join.html).

-# Record the rate at which the system clock gains/losses time.
driftfile /var/lib/chrony/drift

-# Allow the system clock to be stepped in the first three updates
-# if its offset is larger than 1 second.
makestep 1.0 3

-# Enable kernel synchronization of the real-time clock (RTC).
rtcsync

-# Enable hardware timestamping on all interfaces that support it.
-#hwtimestamp *

-# Increase the minimum number of selectable sources required to adjust
-# the system clock.
-#minsources 2

-# Allow NTP client access from local network.
-#allow 192.168.0.0/16

-# Serve time even if not synchronized to a time source.
-#local stratum 10

-# Specify file containing keys for NTP authentication.
keyfile /etc/chrony.keys

-# Get TAI-UTC offset and leap seconds from the system tz database.
leapsectz right/UTC

-# Specify directory for log files.
logdir /var/log/chrony

-# Select which information is logged.
-#log measurements statistics tracking

-###################################################################

2) Replica installed on an existing IdM client.

[root@cypher ~]# ipa-client-install --server mgmt9.rhq.lab.eng.bos.redhat.com --domain rhq.lab.eng.bos.redhat.com
This program will set up FreeIPA client.
Version 4.7.0

Autodiscovery of servers for failover cannot work with this configuration.
If you proceed with the installation, services will be configured to always access the discovered server for all operations and will not fail over to other servers in case of failure.
Proceed with fixed values and no DNS discovery? [no]: yes
Client hostname: cypher.idmqe.lab.eng.bos.redhat.com
Realm: RHQ.LAB.ENG.BOS.REDHAT.COM
DNS Domain: rhq.lab.eng.bos.redhat.com
IPA Server: mgmt9.rhq.lab.eng.bos.redhat.com
BaseDN: dc=rhq,dc=lab,dc=eng,dc=bos,dc=redhat,dc=com

Continue to configure the system with these values? [no]: yes
Synchronizing time
No SRV records of NTP servers found and no NTP server or pool address was provided.
Using default chrony configuration.
Attempting to sync time with chronyc.
Time synchronization was successful.
User authorized to enroll computers: admin
Password for admin@RHQ.LAB.ENG.BOS.REDHAT.COM:
Successfully retrieved CA cert
Subject: CN=Certificate Authority,O=RHQ.LAB.ENG.BOS.REDHAT.COM
Issuer: CN=Certificate Authority,O=RHQ.LAB.ENG.BOS.REDHAT.COM
Valid From: 2018-10-03 14:49:45
Valid Until: 2038-10-03 14:49:45

Enrolled in IPA realm RHQ.LAB.ENG.BOS.REDHAT.COM
Created /etc/ipa/default.conf
Configured sudoers in /etc/nsswitch.conf
Configured /etc/sssd/sssd.conf
Configured /etc/krb5.conf for IPA realm RHQ.LAB.ENG.BOS.REDHAT.COM
Systemwide CA database updated.
Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub
Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub
Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub
Could not update DNS SSHFP records.
WARNING: The configuration pre-client installation is not managed by authselect and cannot be backed up. Uninstallation may not be able to revert to the original state.
SSSD enabled
Configured /etc/openldap/ldap.conf
Configured /etc/ssh/ssh_config
Configured /etc/ssh/sshd_config
Configuring rhq.lab.eng.bos.redhat.com as NIS domain.
Client configuration complete.
The ipa-client-install command was successful

[root@cypher ~]# ipa-replica-install --ntp-server=1.pool.ntp.org
Password for admin@RHQ.LAB.ENG.BOS.REDHAT.COM:
Run connection check to master
Connection check OK
Configuring directory server (dirsrv). Estimated time: 30 seconds
[1/41]: creating directory server instance
[2/41]: enabling ldapi
[3/41]: configure autobind for root
[4/41]: stopping directory server
[5/41]: updating configuration in dse.ldif
[6/41]: starting directory server
[7/41]: adding default schema
[8/41]: enabling memberof plugin
[9/41]: enabling winsync plugin
[10/41]: configuring replication version plugin
[11/41]: enabling IPA enrollment plugin
[12/41]: configuring uniqueness plugin
[13/41]: configuring uuid plugin
[14/41]: configuring modrdn plugin
[15/41]: configuring DNS plugin
[16/41]: enabling entryUSN plugin
[17/41]: configuring lockout plugin
[18/41]: configuring topology plugin
[19/41]: creating indices
[20/41]: enabling referential integrity plugin
[21/41]: configuring certmap.conf
[22/41]: configure new location for managed entries
[23/41]: configure dirsrv ccache
[24/41]: enabling SASL mapping fallback
[25/41]: restarting directory server
[26/41]: creating DS keytab
[27/41]: ignore time skew for initial replication
[28/41]: setting up initial replication
Starting replication, please wait until this has completed.
Update in progress, 8 seconds elapsed
Update succeeded

[29/41]: prevent time skew after initial replication
[30/41]: adding sasl mappings to the directory
[31/41]: updating schema
[32/41]: setting Auto Member configuration
[33/41]: enabling S4U2Proxy delegation
[34/41]: initializing group membership
[35/41]: adding master entry
[36/41]: initializing domain level
[37/41]: configuring Posix uid/gid generation
[38/41]: adding replication acis
[39/41]: activating sidgen plugin
[40/41]: activating extdom plugin
[41/41]: configuring directory to start on boot
Done configuring directory server (dirsrv).
Configuring Kerberos KDC (krb5kdc)
[1/5]: configuring KDC
[2/5]: adding the password extension to the directory
[3/5]: creating anonymous principal
[4/5]: starting the KDC
[5/5]: configuring KDC to start on boot
Done configuring Kerberos KDC (krb5kdc).
Configuring kadmin
[1/2]: starting kadmin
[2/2]: configuring kadmin to start on boot
Done configuring kadmin.
Configuring directory server (dirsrv)
[1/3]: configuring TLS for DS instance
[2/3]: importing CA certificates from LDAP
[3/3]: restarting directory server
Done configuring directory server (dirsrv).
Configuring the web interface (httpd)
[1/21]: stopping httpd
[2/21]: backing up ssl.conf
[3/21]: disabling nss.conf
[4/21]: configuring mod_ssl certificate paths
[5/21]: setting mod_ssl protocol list to TLSv1.0 - TLSv1.2
[6/21]: configuring mod_ssl log directory
[7/21]: disabling mod_ssl OCSP
[8/21]: adding URL rewriting rules
[9/21]: configuring httpd
[10/21]: setting up httpd keytab
[11/21]: configuring Gssproxy
[12/21]: setting up ssl
[13/21]: configure certmonger for renewals
[14/21]: publish CA cert
[15/21]: clean up any existing httpd ccaches
[16/21]: configuring SELinux for httpd
[17/21]: create KDC proxy config
[18/21]: enable KDC proxy
[19/21]: starting httpd
[20/21]: configuring httpd to start on boot
[21/21]: enabling oddjobd
Done configuring the web interface (httpd).
Configuring ipa-otpd
[1/2]: starting ipa-otpd
[2/2]: configuring ipa-otpd to start on boot
Done configuring ipa-otpd.
Configuring ipa-custodia
[1/4]: Generating ipa-custodia config file
[2/4]: Generating ipa-custodia keys
[3/4]: starting ipa-custodia
[4/4]: configuring ipa-custodia to start on boot
Done configuring ipa-custodia.
Configuring certificate server (pki-tomcatd)
[1/2]: configure certmonger for renewals
[2/2]: Importing RA key
Done configuring certificate server (pki-tomcatd).
Configuring Kerberos KDC (krb5kdc)
[1/1]: installing X509 Certificate for PKINIT
Full PKINIT configuration did not succeed
The setup will only install bits essential to the server functionality
You can enable PKINIT after the setup completed using 'ipa-pkinit-manage'
Done configuring Kerberos KDC (krb5kdc).
Applying LDAP updates
Upgrading IPA:. Estimated time: 1 minute 30 seconds
[1/10]: stopping directory server
[2/10]: saving configuration
[3/10]: disabling listeners
[4/10]: enabling DS global lock
[5/10]: disabling Schema Compat
[6/10]: starting directory server
[7/10]: upgrading server
[8/10]: stopping directory server
[9/10]: restoring configuration
[10/10]: starting directory server
Done.
Finalize replication settings
Restarting the KDC

WARNING: The CA service is only installed on one server (mgmt9.rhq.lab.eng.bos.redhat.com).
It is strongly recommended to install it on another server.
Run ipa-ca-install(1) on another master to accomplish this.

[root@cypher ~]# cat /etc/chrony.conf
-# These servers were defined in the installation:
-# Use public servers from the pool.ntp.org project.
-# Please consider joining the pool (http://www.pool.ntp.org/join.html).

-# Record the rate at which the system clock gains/losses time.
driftfile /var/lib/chrony/drift

-# Allow the system clock to be stepped in the first three updates
-# if its offset is larger than 1 second.
makestep 1.0 3

-# Enable kernel synchronization of the real-time clock (RTC).
rtcsync

-# Enable hardware timestamping on all interfaces that support it.
-#hwtimestamp *

-# Increase the minimum number of selectable sources required to adjust
-# the system clock.
-#minsources 2

-# Allow NTP client access from local network.
-#allow 192.168.0.0/16

-# Serve time even if not synchronized to a time source.
-#local stratum 10

-# Specify file containing keys for NTP authentication.
keyfile /etc/chrony.keys

-# Get TAI-UTC offset and leap seconds from the system tz database.
leapsectz right/UTC

-# Specify directory for log files.
logdir /var/log/chrony

-# Select which information is logged.
-#log measurements statistics tracking
[root@cypher ~]#

-###################################################################

Server installation console output:

[root@mgmt9 ~]# ipa-server-install --ntp-server=1.pool.ntp.org

The log file for this installation can be found in /var/log/ipaserver-install.log

This program will set up the FreeIPA Server.
Version 4.7.0

This includes:
* Configure a stand-alone CA (dogtag) for certificate management
* Configure the NTP client (chronyd)
* Create and configure an instance of Directory Server
* Create and configure a Kerberos Key Distribution Center (KDC)
* Configure Apache (httpd)
* Configure the KDC to enable PKINIT

To accept the default shown in brackets, press the Enter key.

Do you want to configure integrated DNS (BIND)? [no]:

Enter the fully qualified domain name of the computer
on which you're setting up server software. Using the form
.
Example: master.example.com.

Server host name [mgmt9.rhq.lab.eng.bos.redhat.com]:

The domain name has been determined based on the host name.

Please confirm the domain name [rhq.lab.eng.bos.redhat.com]:

The kerberos protocol requires a Realm name to be defined.
This is typically the domain name converted to uppercase.

Please provide a realm name [RHQ.LAB.ENG.BOS.REDHAT.COM]:
Certain directory server operations require an administrative user.
This user is referred to as the Directory Manager and has full access
to the Directory for system management tasks and will be added to the
instance of directory server created for IPA.
The password must be at least 8 characters long.

Directory Manager password:
Password (confirm):

The IPA server requires an administrative user, named 'admin'.
This user is a regular system account used for IPA server administration.

IPA admin password:
Password (confirm):

The IPA Master Server will be configured with:
Hostname: mgmt9.rhq.lab.eng.bos.redhat.com
IP address(es): 10.16.4.19
Domain name: rhq.lab.eng.bos.redhat.com
Realm name: RHQ.LAB.ENG.BOS.REDHAT.COM

The CA will be configured with:
Subject DN: CN=Certificate Authority,O=RHQ.LAB.ENG.BOS.REDHAT.COM
Subject base: O=RHQ.LAB.ENG.BOS.REDHAT.COM
Chaining: self-signed

Continue to configure the system with these values? [no]: yes

The following operations may take some minutes to complete.
Please wait until the prompt is returned.

Synchronizing time
Configuration of chrony was changed by installer.
Attempting to sync time with chronyc.
Time synchronization was successful.
Configuring directory server (dirsrv). Estimated time: 30 seconds
[1/44]: creating directory server instance
[2/44]: enabling ldapi
[3/44]: configure autobind for root
*
*
*
*
Please add records in this file to your DNS system: /tmp/ipa.system.records.af3cbvc7.db
==============================================================================
Setup complete
*
*
The ipa-server-install command was successful

[root@mgmt9 ~]# cat /etc/chrony.conf
-# These servers were defined in the installation:
-# Use public servers from the pool.ntp.org project.
-# Please consider joining the pool (http://www.pool.ntp.org/join.html).

-# Record the rate at which the system clock gains/losses time.
driftfile /var/lib/chrony/drift

-# Allow the system clock to be stepped in the first three updates
-# if its offset is larger than 1 second.
makestep 1.0 3

-# Enable kernel synchronization of the real-time clock (RTC).
rtcsync

-# Enable hardware timestamping on all interfaces that support it.
-#hwtimestamp *

-# Increase the minimum number of selectable sources required to adjust
-# the system clock.
-#minsources 2

-# Allow NTP client access from local network.
-#allow 192.168.0.0/16

-# Serve time even if not synchronized to a time source.
-#local stratum 10

-# Specify file containing keys for NTP authentication.
keyfile /etc/chrony.keys

-# Get TAI-UTC offset and leap seconds from the system tz database.
leapsectz right/UTC

-# Specify directory for log files.
logdir /var/log/chrony

-# Select which information is logged.
-#log measurements statistics tracking
server 1.pool.ntp.org iburst


The client installer handles the NTP server/pool configuration.

There are two separate issues:

  1. If not enrolling on a pre-configured client then the ntp-server and ntp-pool options are not being passed down to the client installer invocation.
  2. If the client is already enrolled then the ntp options are ignored altogether.

Metadata Update from @rcritten:
- Issue assigned to rcritten

https://github.com/freeipa/freeipa/pull/2451

Metadata Update from @rcritten:
- Issue priority set to: normal
- Issue set to the milestone: FreeIPA 4.7.2

For the first case we can pass the NTP options down to the client installer.

For the second case (pre-enrolled) we will raise an exception. There are a bunch of corner cases and it is just far easier to uninstall and re-install the client to change the NTP config (or do manual changes).

master:

  • 2fba5acc5245caf62ec9af8b8707c13f59bfcff4 Handle NTP configuration in a replica server installation

ipa-4-7:

  • f3e3da509329881c4ba770d1f9418ad180ee98ae Handle NTP configuration in a replica server installation

Metadata Update from @rcritten:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata Update from @rcritten:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1651679

Issue linked to Bugzilla: Bug 1651679

master:

  • dde2aa4b16b10f39ed595fef4d2425a4229fd7d5 ipatests: add tests for NTP options usage on server, replica, and client
  • 715d1223dd8d38c12c5a2812248288b20465fafb nightly_master.yaml Added test_integration/test_ntp_options.py
  • 83487c49f69c6ceef3fddc0c176027c4bed7aab4 nightly_rawhide.yaml Added test_integration/test_ntp_options.py

ipa-4-7:

  • 5cacd1357875606537c8f88242afded4949e6486 ipatests: add tests for NTP options usage on server, replica, and client
  • 4714c543dab4230f5b0d68ac6a04ad7c0b3f8f2b nightly_master.yaml Added test_integration/test_ntp_options.py
  • d02e0c367850bac308afb16afa748689732b269c nightly_rawhide.yaml Added test_integration/test_ntp_options.py
  • 657fc760dab834f352a552cba486e69e80c676c0 Fix test_ntp_options to use tasks' methods
Metadata