[Bug 1102885] New: upgrade from 42.3 to 15,0 breaks kerberos/ldaps auth-server
http://bugzilla.opensuse.org/show_bug.cgi?id=1102885 Bug ID: 1102885 Summary: upgrade from 42.3 to 15,0 breaks kerberos/ldaps auth-server Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.0 Hardware: x86-64 OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Other Assignee: bnc-team-screening@forge.provo.novell.com Reporter: falk.schoenfeld@web.de QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- After upgrade my Auth-Server with LDAP/Kerberos from Leap 42.3 to 15.0, kerberos-server is unable to start. /var/log/krb5/krb5kdc.log: krb5kdc: Unable to load requested database module 'kldap': plugin symbol 'kdb_function_table' not found - while initializing database for realm XXX krb5kdc: Cannot bind to LDAP server 'ldapi:///' as 'cn=Administrator,dc=xxx,dc=de': Invalid credentials - while initializing database for realm XXX krb5kdc: Cannot open DB2 database '/var/lib/kerberos/krb5kdc/principal': No such file or directory - while initializing database for realm XXX A clean fresh inst of leap 15.0 does not contain kldap.so in /usr/lib64/krb5/plugins/kdb/ so I guess the LDAP-support is missing for MIT-KRB -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1102885 http://bugzilla.opensuse.org/show_bug.cgi?id=1102885#c2 --- Comment #2 from Falk Schönfeld <falk.schoenfeld@web.de> --- It was installed, but not upgraded. After reinstalling krb5-plugin-kdb-ldap the error of the unknown symbol 'kdb_function_table' disappeared, but krb ist still broken and not starting. krb logs says: krb5kdc: Cannot bind to LDAP server 'ldapi:///' as 'cn=Administrator,dc=xxx,dc=de': Invalid credentials - while initializing database for realm XXX.DE -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1102885 http://bugzilla.opensuse.org/show_bug.cgi?id=1102885#c4 --- Comment #4 from Falk Schönfeld <falk.schoenfeld@web.de> --- I changed all files under /etc/zypp/repos.d from 42.3 to 15.0 then I did a zypper cc ; zypper ref; zypper dup after that, the kldap.so was still from february and I had the error of the unknown symbol. I made a new installation in a vm and copied the file manualy to my auth-server. The error is gone, but krb ist still not starting because "invalid credentials". I cant figure out why. Maybe something in the configuration has changed. Whether its a bug or a feature, and then I think it should be mentioned in the release notes. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com