IPA server is running slow and seeing lots of transaction logs being created

Solution Verified - Updated -

Issue

IPA server is running slow and seeing lots of transaction log being created under /var/lib/dirsrv/slapd-instance_name/db/log.*
Due to the slowness of the server , we are seeing High I/O wait and also replication is not working as expected.

Recently customer promoted a Replica IPA server to a Master.

/var/lib/dirsrv/slapd-instance_name/db/log.xxxx shows the following :

userCertificate;vucsn-56a20d00000900030000;deleted:: MIID2DCCAsCgAwIBAgIFAmhD3
 jowDQYJKoZIhvcNAQELBQAwRDEiMCAGA1UEChMZTEFTLlZJUlRVQUxEUkVBTVdPUktTLkNPTTEeMB
 wGA1UEAxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDEyMjExMDUzM1oXDTE4MDEyMjExMDU

userCertificate;vucsn-56a20e99000200030000;deleted:: MIID2DCCAsCgAwIBAgIFAmhD3
 pswDQYJKoZIhvcNAQELBQAwRDEiMCAGA1UEChMZTEFTLlZJUlRVQUxEUkVBTVdPUktTLkNPTTEeMB
 wGA1UEAxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDEyMjExMTIyNFoXDTE4MDEyMjExMTI

/var/log/pki-ca/transactions logs shows the following occurring at a high frequency.

25530.TP-Processor16 - [26/Jan/2016:02:43:30 UTC] [20] [1] Revocation request reqID 30154878 fromAgent agentID: ipara authenticated by certUserDBAuthMgr is completed. DN requested: CN=ipaclient.example.com,O=EXAMPLE.COM serial number: 0x268448369 revocation reason: Superseded time: 9
25530.TP-Processor19 - [26/Jan/2016:02:43:31 UTC] [20] [1] enrollment reqID 30154879 fromAgent userID: ipara authenticated by raCertAuth is completed DN requested: CN=ipaclient.example.com,O=EXAMPLE.COM cert issued serial number: 0x26844836b time: 8

Environment

  • Red Hat Enterprise Linux 6

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.