#9426 Update FreeIPA service issue named
Closed: invalid by abbra. Opened by bob360.

Request for enhancement

As an admin system from a University, I want help so that users can connect again to the system.

Issue

We had 4 replicas FreeIPA with Centos 7, and we wanted to update it to AlmaLinux 8. So we uninstalled one by one each server and re installed it to Alma 8. After the updated of 3 of the servers, all services were running correctly. When we updated the last FreeIPA server to Alma 8, the issues started.

  1. ipactl start can't start the named service
  2. in the log /var/log/dirsrv/slapd-MYDOMAIN-CH/errors : "ERR - set_krb5_creds - Could not get initial credentials for principal [ldap/ipa01.astro.unige.ch@MYDOMAIN.CH] in keytab [FILE:/etc/dirsrv/ds.keytab]: -1765328360 (Preauthentication failed)"

Steps to Reproduce

  1. Add new replicas
  2. Delete old replicas

Actual behavior

The internal DNS does not work anymore and user's authentication does not work too.

Expected behavior

ipa services should work as before.

Version/Release/Distribution

$ rpm -q freeipa-server freeipa-client ipa-server ipa-client 389-ds-base pki-ca krb5-server
package freeipa-server is not installed
package freeipa-client is not installed
ipa-server-4.9.11-6.module_el8.8.0+3593+1210bde8.alma.1.x86_64
ipa-client-4.9.11-6.module_el8.8.0+3593+1210bde8.alma.1.x86_64
389-ds-base-1.4.3.35-1.module_el8.8.0+3584+33666a53.x86_64
package pki-ca is not installed
krb5-server-1.18.2-25.el8_8.x86_64


Hello. Please use freeipa-users@ mailing list to request an operational help.

Please make sure to collect and provide logs. Best is to collect sosreport output and make it available somewhere.

I am closing this issue as invalid. This issue tracker is used to track software changes in FreeIPA.

Metadata Update from @abbra:
- Issue close_status updated to: invalid
- Issue status updated to: Closed (was: Open)

Metadata