#4794 IPA 4-1 replica unable to replicate to IPA-3-0 master
Closed: Fixed None Opened 9 years ago by pvoborni.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1167964

Description of problem:

I'm seeing issues with replication between new RHEL7.1 IPA replica added to
environment with IPA master on RHEL6.6.

[25/Nov/2014:20:49:39 +051800] NSMMReplicationPlugin -
multimaster_be_state_change: replica dc=testrelm
,dc=test is coming online; enabling replication
[25/Nov/2014:20:49:39 +051800] - Skipping CoS Definition cn=Password
Policy,cn=accounts,dc=testrelm,dc=
test--no CoS Templates found, which should be added before the CoS Definition.
[25/Nov/2014:20:49:41 +051800] NSMMReplicationPlugin - [S] Schema
agmt="cn=meTovm-idm-052.testrelm.test
" (vm-idm-052:389) must not be overwritten (set replication log for additional
info)
[25/Nov/2014:20:49:42 +051800] NSMMReplicationPlugin - [S] Schema
agmt="cn=meTovm-idm-052.testrelm.test
" (vm-idm-052:389) must not be overwritten (set replication log for additional
info)
[25/Nov/2014:20:49:42 +051800] NSMMReplicationPlugin -
agmt="cn=meTovm-idm-052.testrelm.test" (vm-idm-0
52:389): Warning: unable to replicate schema: rc=1

Version-Release number of selected component (if applicable):
Master (rhel6.6):
ipa-server-3.0.0-42.el6.x86_64
389-ds-base-1.2.11.15-48.el6_6.x86_64

Replica (rhel7.1):
ipa-server-4.1.0-7.el7.x86_64
389-ds-base-1.3.3.1-9.el7.x86_64

How reproducible:
always

Steps to Reproduce:
1.  setup IPA master on RHEL6.6 server
2.  setup IPA replica on RHEL7.1 server
3.

Actual results:
errors in log file and

Expected results:


Additional info:
getting more logs and replication debugging information that I will attach.

Probable reasons investigated by Thierry:

Replication is failing because of schema problems

  • schema 6.6 allows 'cn' in idnsRecord (but not 7.1)
  • schema 7.1 allows DLVRecord and TLSARecord (but not 6.6)

  • nsViewFilter and mgrpRFC822MailMember

    • IA5String syntax in 6.6
    • DirectoryString in 7.1
  • DirectoryString is seen as a superset of IA5String

master:

  • 489dfe6 revert removal of cn attribute from idnsRecord

ipa-4-1:

  • 2fa07b1 revert removal of cn attribute from idnsRecord

Metadata Update from @pvoborni:
- Issue assigned to pvoborni
- Issue set to the milestone: FreeIPA 4.1.3

7 years ago

Login to comment on this ticket.

Metadata