IPA replication break issue: No data, user and group disappear, missing index
Environment
- RHEL8/9
- IPA
Issue
- IPA commands do not return the expected results.
# ipa hbacrule-find
# ipa sudorule-find
# ipa user-find --all
# ipa host-find --all
-
Missing "Partent ID" attribute
-
Missing "ancestorid " attribute
-
dsctl
healthcheck returns an error:
The following system indexes should be present with correct configuration:
- entryrdn: index type 'subtree'
- parentid: index type 'eq' with matching rule 'integerOrderingMatch'
- ancestorid: index type 'eq' with matching rule 'integerOrderingMatch'
- objectClass: index type 'eq'
- aci: index type 'pres'
- nscpEntryDN: index type 'eq'
- nsUniqueId: index type 'eq'
- nsds5ReplConflict: index types 'eq', 'pres'
- nsCertSubjectDN: index type 'eq'
- numsubordinates: index type 'pres'
- nsTombstoneCSN: index type 'eq'
- targetuniqueid: index type 'eq'
- entryusn: index type 'eq' with matching rule 'integerOrderingMatch'
Current discrepancies:
- Index parentid missing matching rule: integerOrderingMatch
- Index parentid missing fine grain definition of IDs limit: integerOrderingMatch
CRITICAL: ipahealthcheck.ds.backends.BackendsCheck.DSBLE0007: System indexes are essential for proper directory server operation. Missing or
incorrectly configured system indexes can lead to poor search performance, replication
issues, and other operational problems.
Resolution
- This issue is being tracked in Jira: RHEL-137786
- For RHEL8.10, Issue has been fixed with the version : 389-ds-base-1.4.3.39-22.module+el8.10.0+24000+b6bfdf3f.x86_64.rpm
- It can be downloaded from errata: RHBA-2026:3126
Manual Fix
- Need to do re-inedexing after adding attribute for ipaca, UserRoot and changelog with respect to "parentid" and "ancestorid"
For "parentid"
[+] IPACA : "o=ipaca"
#dsconf EXAMPLE1 backend index delete ipaca --attr parentid
#dsconf EXAMPLE1 backend index add ipaca --attr parentid --index-type eq --matching-rule integerOrderingMatch
#dsconf EXAMPLE1 backend index set ipaca --attr parentid --add-scanlimit limit=5000
#dsconf EXAMPLE1 backend index reindex ipaca --attr parentid
[+] UserRoot :
#dsconf EXAMPLE1 backend index delete userroot --attr parentid
#dsconf EXAMPLE1 backend index add userroot --attr parentid --index-type eq --matching-rule integerOrderingMatch
#dsconf EXAMPLE1 backend index set userroot --attr parentid --add-scanlimit limit=5000
#dsconf EXAMPLE1 backend index reindex userroot --attr parentid
[+] changelog
#dsconf EXAMPLE1 backend index delete changelog --attr parentid
#dsconf EXAMPLE1 backend index add changelog --attr parentid --index-type eq --matching-rule integerOrderingMatch
#dsconf EXAMPLE1 backend index set changelog --attr parentid --add-scanlimit limit=5000
#dsconf EXAMPLE1 backend index reindex changelog --attr parentid
For "ancestorid"
[+] IPACA : "o=ipaca"
#dsconf EXAMPLE1 backend index delete ipaca --attr ancestorid
#dsconf EXAMPLE1 backend index add ipaca --attr ancestorid --index-type eq --matching-rule integerOrderingMatch
#dsconf EXAMPLE1 backend index set ipaca --attr ancestorid --add-scanlimit limit=5000
#dsconf EXAMPLE1 backend index reindex ipaca --attr ancestorid
[+] UserRoot :
#dsconf EXAMPLE1 backend index delete userroot --attr ancestorid
#dsconf EXAMPLE1 backend index add userroot --attr ancestorid --index-type eq --matching-rule integerOrderingMatch
#dsconf EXAMPLE1 backend index set userroot --attr ancestorid --add-scanlimit limit=5000
#dsconf EXAMPLE1 backend index reindex userroot --attr ancestorid
[+] changelog
#dsconf EXAMPLE1 backend index delete changelog --attr ancestorid
#dsconf EXAMPLE1 backend index add changelog --attr ancestorid --index-type eq --matching-rule integerOrderingMatch
#dsconf EXAMPLE1 backend index set changelog --attr ancestorid --add-scanlimit limit=5000
#dsconf EXAMPLE1 backend index reindex changelog --attr ancestorid
Note. "EXAMPLE1" means Directory server instances.
Root Cause
-
After updating the 389-ds-base package to a version that adds the integerOrderingMatch matching rule to the parentid and ancestorid indexes, searches may return empty or incorrect results.
-
This happens because the existing index data was created with lexicographic ordering, but the new compare function expects integer ordering.
Diagnostic Steps
- check if ipa user-find gives empty result
-Check if HBAC Rules or Sudo Rules are listed using ipa hbacrule-find and ipa sudocrule-find - system indexes are missing
- entryrdn: index type 'subtree'
- parentId: index type 'eq'
This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.
Comments