#7083 failed ipa-server-upgrade , time out from dogtag services , custodia errors
Closed: fixed Opened by pvoborni.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1477367

Description of problem:
failed "yum ipa-*" from RHEL-7.3 to new 7.4
difficulties around the dogtag services, the start from
/bin/systemctl start pki-tomcatd@pki-tomcat.service
may not have happened correctly:
2017-08-01T15:33:23Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout
300
2017-08-01T15:38:23Z ERROR IPA server upgrade failed: Inspect
/var/log/ipaupgrade.log and run command ipa-server-upgrade manually.
2017-08-01T15:38:23Z DEBUG   File
"/usr/lib/python2.7/site-packages/ipapython/admintool.py", line 172, in execute
    return_value = self.run()
  File
"/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_upgrade.py",
line 46, in run
    server.upgrade()
  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/upgrade.py",
line 1913, in upgrade
    upgrade_configuration()
  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/upgrade.py",
line 1646, in upgrade_configuration
    upgrade_pki(ca, fstore)
  File "/usr/lib64/python2.7/contextlib.py", line 24, in __exit__
    self.gen.next()
  File "/usr/lib/python2.7/site-packages/ipaserver/install/installutils.py",
line 1134, in stopped_service
    service_obj.start(instance_name)
  File "/usr/lib/python2.7/site-packages/ipaplatform/redhat/services.py", line
211, in start
    instance_name, capture_output=capture_output, wait=wait)
  File "/usr/lib/python2.7/site-packages/ipaplatform/base/services.py", line
300, in start
    self.wait_for_open_ports(self.service_instance(instance_name))
  File "/usr/lib/python2.7/site-packages/ipaplatform/base/services.py", line
270, in wait_for_open_ports
    self.api.env.startup_timeout)
  File "/usr/lib/python2.7/site-packages/ipapython/ipautil.py", line 1227, in
wait_for_open_ports
    raise socket.timeout("Timeout exceeded")
2017-08-01T15:38:23Z DEBUG The ipa-server-upgrade command failed, exception:
timeout: Timeout exceeded
2017-08-01T15:38:23Z ERROR Timeout exceeded
Version-Release number of selected component (if applicable):
custodia-0.3.1-4.el7.noarch                                 Tue Aug  1 05:36:02
2017
ipa-server-4.5.0-20.el7.x86_64                              Tue Aug  1 05:36:39
2017
redhat-release-server-7.4-18.el7.x86_64                     Tue Aug  1 05:34:46
2017
Later investigation shows that the ports were open.

Metadata Update from @pvoborni:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1477367

Metadata Update from @pvoborni:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1477367

Metadata Update from @pvoborni:
- Issue assigned to pvoborni

Metadata Update from @tkrizek:
- Issue priority set to: critical
- Issue set to the milestone: FreeIPA 4.5

master:

  • cc72db67e2eaede577c3129d572b85e9c2ba593c control logging of host_port_open from caller
  • 038d1920657c6fd349f8414ed173a9c97681a602 log progress of wait_for_open_ports

Metadata Update from @tkrizek:
- Issue set to the milestone: FreeIPA 4.5.4 (was: FreeIPA 4.5)

master:

  • dc47a4b85f289e8acfaf507d94f991570f04bd03 Make sure upgrade also checks for IPv6 stack

ipa-4-5:

  • bdf9a34dffdf4d7925208e5df9f69e3927b88858 Make sure upgrade also checks for IPv6 stack

ipa-4-5:

  • b5970862a5b22c4272c00be1d31e1d50f3b7c14c control logging of host_port_open from caller
  • 756734351410077ab7b102a9a7a5264a62bcb0e0 log progress of wait_for_open_ports

ipa-4-6:

  • f05afa4813f425e9fc9960f63100431a78310638 Make sure upgrade also checks for IPv6 stack

Metadata Update from @tkrizek:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata