IPA server is running slow and seeing lots of transaction logs being created
Issue
IPA server is running slow and seeing lots of transaction log being created under /var/lib/dirsrv/slapd-instance_name/db/log.*
Due to the slowness of the server , we are seeing High I/O wait and also replication is not working as expected.
Recently customer promoted a Replica IPA server to a Master.
/var/lib/dirsrv/slapd-instance_name/db/log.xxxx shows the following :
userCertificate;vucsn-56a20d00000900030000;deleted:: MIID2DCCAsCgAwIBAgIFAmhD3
jowDQYJKoZIhvcNAQELBQAwRDEiMCAGA1UEChMZTEFTLlZJUlRVQUxEUkVBTVdPUktTLkNPTTEeMB
wGA1UEAxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDEyMjExMDUzM1oXDTE4MDEyMjExMDU
userCertificate;vucsn-56a20e99000200030000;deleted:: MIID2DCCAsCgAwIBAgIFAmhD3
pswDQYJKoZIhvcNAQELBQAwRDEiMCAGA1UEChMZTEFTLlZJUlRVQUxEUkVBTVdPUktTLkNPTTEeMB
wGA1UEAxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDEyMjExMTIyNFoXDTE4MDEyMjExMTI
/var/log/pki-ca/transactions logs shows the following occurring at a high frequency.
25530.TP-Processor16 - [26/Jan/2016:02:43:30 UTC] [20] [1] Revocation request reqID 30154878 fromAgent agentID: ipara authenticated by certUserDBAuthMgr is completed. DN requested: CN=ipaclient.example.com,O=EXAMPLE.COM serial number: 0x268448369 revocation reason: Superseded time: 9
25530.TP-Processor19 - [26/Jan/2016:02:43:31 UTC] [20] [1] enrollment reqID 30154879 fromAgent userID: ipara authenticated by raCertAuth is completed DN requested: CN=ipaclient.example.com,O=EXAMPLE.COM cert issued serial number: 0x26844836b time: 8
Environment
- Red Hat Enterprise Linux 6
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.