pki-tomcat サービスが IPA レプリカでの起動に失敗し、"netscape.ldap.LDAPException: Authentication failed (48)" エラーを表示する
Issue
-
認証エラーにより pki-tomcat サービスを開始できないため、ipactl restart コマンドが失敗します。
- デバッグログには以下のエラーが表示されます。
[06/Jun/2017:12:46:18][localhost-startStop-1]: SSLClientCertificateSelectionCB: Setting desired cert nickname to: subsystemCert cert-pki-ca
[06/Jun/2017:12:46:18][localhost-startStop-1]: LdapJssSSLSocket: set client auth cert nickname subsystemCert cert-pki-ca
[06/Jun/2017:12:46:18][localhost-startStop-1]: SSLClientCertificatSelectionCB: Entering!
[06/Jun/2017:12:46:18][localhost-startStop-1]: SSLClientCertificateSelectionCB: returning: null
[06/Jun/2017:12:46:18][localhost-startStop-1]: SSL handshake happened
Could not connect to LDAP server host server.exampale.com port 636 Error netscape.ldap.LDAPException: Authentication failed (48)
at com.netscape.cmscore.ldapconn.LdapBoundConnFactory.makeConnection(LdapBoundConnFactory.java:205)
Environment
- Red Hat Enterprise Linux Server リリース 7 (rhel 7)
- ipa-server-4.X
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.