Skip navigation

Lion OD replica problem

1325 Views 9 Replies Latest reply: Sep 22, 2012 5:05 AM by rockhill04 RSS
Joe Swenson Level 3 Level 3 (735 points)
Currently Being Moderated
Feb 6, 2012 2:09 PM

slapconfig -createreplica --certAdminEmail username@university.edu cpstudx1.domain.priv diradmin

diradmin's Password:

2012-02-06 21:49:49 +0000 command: /usr/sbin/sso_util info -r /LDAPv3/ldap://cpstudx1.domain.priv -p

sso_util command failed with status 2

2012-02-06 21:49:49 +0000 _preflightLDAPReplica: could not read the Kerberos realm from the master cpstudx1.domain.priv

2012-02-06 21:49:49 +0000 Not creating replica due to failure to read Kerberos realm from master. (error = 78)

2012-02-06 21:49:49 +0000 Not creating replica due to preflight failure.

2012-02-06 21:49:49 +0000 Not creating replica due to preflight failure. (error = 78)

 

I had this system as a replica, I demoted it from replica status in an apparently vain attempt to see if I could clear up all these errors:

 

Feb  6 16:03:10 cpstudx1 slapd[1058]: slap_client_connect: URI=ldap://MASTUDXM.local:389 ldap_sasl_interactive_bind_s failed (-1)

Feb  6 16:03:10 cpstudx1 slapd[1058]: do_syncrepl1: client_connect failed (-1)

Feb  6 16:03:10 cpstudx1 slapd[1058]: do_syncrepl: rid=005 rc -1 retrying

Feb  6 16:03:10 cpstudx1 slapd[1058]: slap_client_connect: URI=ldap://BCSTUDXM.DOMAIN.PRIV:389 ldap_sasl_interactive_bind_s failed (-2)

Feb  6 16:03:10 cpstudx1 slapd[1058]: do_syncrepl1: client_connect failed (-1)

Feb  6 16:03:10 cpstudx1 slapd[1058]: do_syncrepl: rid=002 rc -1 retrying

Feb  6 16:03:10 cpstudx1 slapd[1058]: slap_client_connect: URI=ldap://erstudxm.domain.priv:389 ldap_sasl_interactive_bind_s failed (-2)

Feb  6 16:03:10 cpstudx1 slapd[1058]: do_syncrepl1: client_connect failed (-1)

Feb  6 16:03:10 cpstudx1 slapd[1058]: do_syncrepl: rid=003 rc -1 retrying

Feb  6 16:03:11 cpstudx1 slapd[1058]: SASL [conn=1279] Failure: incorrect digest response

 

Anyone have useful thoughts? Thanks

Mac OS X (10.7.3)
  • bezzoh Calculating status...
    Currently Being Moderated
    Jul 26, 2012 3:13 AM (in response to Joe Swenson)

    Exactly the same issues with the 1 replica i managed to join to my Master. Further to this i am unable to add additional replicas, getting an error that I cant authenticate as diradmin as it may not be a Directory Administrator. Getting on my nerves now.

  • bezzoh Level 1 Level 1 (0 points)
    Currently Being Moderated
    Jul 26, 2012 8:56 AM (in response to Joe Swenson)

    That explains a few things then as i was importing computer groups originally. I have since today however abandoned all hope of complete replication however and reverted to each site having a standalone server. Reason being, once i had gotten a server replicated the one time replication worked fine, however subsequent ones did not and the LDAP log consistenly gets full of ldap_sasl_interactive_bind_s failed errors on both the master and replica.

     

    Unless you have any insight on this also, i'm unfortunately stuck with multiple masters at each customer site (which is a real pain for management).

     

    Thanks for your response however, that did at least explain how I got 1 server connected this morning (as i'd actually demoted that one when in 10.6 prior to the 10.7 install.

  • bezzoh Level 1 Level 1 (0 points)
    Currently Being Moderated
    Jul 26, 2012 9:44 AM (in response to Joe Swenson)

    I read that earlier today. Maybe it is related to SSL (None of the other solutions worked for me), however I havent even enabled SSL on my master, so I didnt think this would be the cause. I may do some more digging.... Or upgrade to 10.8 haha

  • bezzoh Level 1 Level 1 (0 points)
    Currently Being Moderated
    Jul 26, 2012 11:30 AM (in response to Joe Swenson)

    I'll give it a crack tomorrow then and let you know how I get on...

  • rockhill04 Level 1 Level 1 (0 points)
    Currently Being Moderated
    Sep 22, 2012 5:05 AM (in response to Joe Swenson)

    I tried your suggestion and I am down to this error. Any feedback on how to fix this. The OD Master is brand new installed.

     

    sso_util command failed with status 2

    2012-09-22 11:58:53 +0000 _preflightLDAPReplica: could not read the Kerberos realm from the master server.mydomain.com

    2012-09-22 11:58:53 +0000 Not creating replica due to failure to read Kerberos realm from master. (error = 78)

    2012-09-22 11:58:53 +0000 Not creating replica due to preflight failure.

    2012-09-22 11:58:53 +0000 Not creating replica due to preflight failure. (error = 78)

     

    Thanks in advance for any feedback.

     

    running 10.7.5

Actions

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • This solved my question - 10 points
  • This helped me - 5 points
This site contains user submitted content, comments and opinions and is for informational purposes only. Apple disclaims any and all liability for the acts, omissions and conduct of any third parties in connection with or related to your use of the site. All postings and use of the content on this site are subject to the Apple Support Communities Terms of Use.