在安装ipa多主时:

ipa-replica-install –setup-dns –forwarder 8.8.8.8 –setup-ca –auto-reverse –principal admin –admin-password XXXXX

执行以上命令安装时, 一直在报错:

查了下google, 终于找到一篇文章: https://pagure.io/freeipa/issue/6613

具体就是: pki-tomcat的8009端口没启来, 原因是:

This is a duplicate of https://fedorahosted.org/freeipa/ticket/6575.

We’re working on a fix. As mentioned in comment:16, changing ::1 to localhost or 127.0.0.1 in /var/lib/pki/pki-tomcat/conf/server.xml in ‘address’ field of AJP/1.3 Connector fixes the issue.

netstat -tupnl | grep 8009

开始修改:

vim /var/lib/pki/pki-tomcat/conf/server.xml

<Connector port=”8009″ protocol=”AJP/1.3″ redirectPort=”8443″ address=”::1″ />

改为:

<Connector port=”8009″ protocol=”AJP/1.3″ redirectPort=”8443″ address=”127.0.0.1″ />

重启ipa:

ipactl restart

查看端口:

[root@jump1-iuap-hb2-ali tomcat]# netstat -tupnl | grep 8009
tcp 0 0 127.0.0.1:8009 0.0.0.0:* LISTEN 25314/java

8009已经启来了, 再次重试安装replica, 大功告成!

注: 安装replica, 千万别忘加–setup-dns –forwarder 8.8.8.8 –setup-ca 参数!!!!

 

repelica安装失败, 一般是缺少目录:

解决方法:
mkdir /etc/krb5.conf.d
mkdir /var/log/sssd
mkdir -p /etc/ipa/nssdb/
mkdir -p /var/lib/ipa-client/sysrestore/
mkdir -p /etc/ipa/custodia
mkdir -p /var/lib/ipa/sysrestore
mkdir -p /var/lib/ipa/sysupgrade/
mkdir -p /etc/ipa/kdcproxy
mkdir -p /var/lib/ipa/pki-ca
mkdir -p /etc/ipa/dnssec
Categories: 未分类

2 Comments

Vince Raspberry · 06/22/2020 at 5:35 PM

This will be a terrific website, would you be interested in doing an interview about how you designed it? If so e-mail me!

Anthony Pantaleon · 07/04/2020 at 9:18 PM

It’s actually a nice and useful piece of info. I’m happy that you shared this useful info with us. Please stay us up to date like this. Thank you for sharing.

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *