IPA server is running slow and seeing lots of transaction logs being created
Issue
IPA server is running slow and seeing lots of transaction log being created under /var/lib/dirsrv/slapd-instance_name/db/log.*
Due to the slowness of the server , we are seeing High I/O wait and also replication is not working as expected.
Recently customer promoted a Replica IPA server to a Master.
/var/lib/dirsrv/slapd-instance_name/db/log.xxxx shows the following :
userCertificate;vucsn-56a20d00000900030000;deleted:: MIID2DCCAsCgAwIBAgIFAmhD3
jowDQYJKoZIhvcNAQELBQAwRDEiMCAGA1UEChMZTEFTLlZJUlRVQUxEUkVBTVdPUktTLkNPTTEeMB
wGA1UEAxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDEyMjExMDUzM1oXDTE4MDEyMjExMDU
userCertificate;vucsn-56a20e99000200030000;deleted:: MIID2DCCAsCgAwIBAgIFAmhD3
pswDQYJKoZIhvcNAQELBQAwRDEiMCAGA1UEChMZTEFTLlZJUlRVQUxEUkVBTVdPUktTLkNPTTEeMB
wGA1UEAxMVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE2MDEyMjExMTIyNFoXDTE4MDEyMjExMTI
/var/log/pki-ca/transactions logs shows the following occurring at a high frequency.
25530.TP-Processor16 - [26/Jan/2016:02:43:30 UTC] [20] [1] Revocation request reqID 30154878 fromAgent agentID: ipara authenticated by certUserDBAuthMgr is completed. DN requested: CN=ipaclient.example.com,O=EXAMPLE.COM serial number: 0x268448369 revocation reason: Superseded time: 9
25530.TP-Processor19 - [26/Jan/2016:02:43:31 UTC] [20] [1] enrollment reqID 30154879 fromAgent userID: ipara authenticated by raCertAuth is completed DN requested: CN=ipaclient.example.com,O=EXAMPLE.COM cert issued serial number: 0x26844836b time: 8
Environment
- Red Hat Enterprise Linux 6
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
