#9557 Replica installation cannot register DNS record for itself
Opened by abbra. Modified

In CI logs:

2024-03-15T13:22:44Z DEBUG Logging to /var/log/ipareplica-install.log
2024-03-15T13:22:44Z DEBUG ipa-replica-install was invoked with arguments [] and options: {'unattended': True, 'ip_addresses': [CheckedIPAddress('192.168.121.173')], 'domain_name': 'ipa.test', 'servers': None, 'realm_name': 'IPA.TEST', 'host_name': None, 'principal': None, 'hidden_replica': False, 'setup_adtrust': False, 'setup_ca': True, 'setup_kra': False, 'setup_dns': True, 'no_pkinit': False, 'no_ui_redirect': False, 'dirsrv_config_file': '/ipatests/ipatests_dse.ldif', 'skip_mem_check': False, 'dirsrv_cert_files': None, 'http_cert_files': None, 'pkinit_cert_files': None, 'dirsrv_cert_name': None, 'http_cert_name': None, 'pkinit_cert_name': None, 'keytab': None, 'mkhomedir': False, 'force_join': False, 'ntp_servers': None, 'ntp_pool': None, 'no_ntp': False, 'force_ntpd': False, 'ssh_trust_dns': False, 'no_ssh': False, 'no_sshd': False, 'subid': False, 'no_dns_sshfp': False, 'skip_schema_check': False, 'pki_config_override': None, 'allow_zone_overlap': False, 'reverse_zones': None, 'no_reverse': False, 'auto_reverse': False, 'forwarders': [CheckedIPAddressLoopback('192.168.121.1')], 'no_forwarders': False, 'auto_forwarders': False, 'forward_policy': None, 'no_dnssec_validation': False, 'no_host_dns': False, 'add_agents': False, 'enable_compat': False, 'no_msdcs': False, 'skip_conncheck': False, 'add_sids': False, 'netbios_name': None, 'rid_base': None, 'secondary_rid_base': None, 'verbose': False, 'quiet': False, 'log_file': None}
2024-03-15T13:22:44Z DEBUG IPA version 4.12.0.dev-0.fc39
...
2024-03-15T13:23:36Z DEBUG raw: dnsrecord_add('ipa.test', 'replica0', arecord='192.168.121.173', version='2.253')
2024-03-15T13:23:36Z DEBUG dnsrecord_add(<DNS name ipa.test.>, <DNS name replica0>, arecord=('192.168.121.173',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version='2.253')
2024-03-15T13:23:36Z INFO Replica DNS records could not be added on master: Insufficient access: Insufficient 'add' privilege to add the entry 'idnsname=replica0,idnsname=ipa.test.,cn=dns,dc=ipa,dc=test'.

This is from http://freeipa-org-pr-ci.s3-website.eu-central-1.amazonaws.com/jobs/9a828daa-e2cd-11ee-96d2-fa163ec210a9/test_integration-test_dnssec.py-TestInstallDNSSECFirst-test_servers_use_localhost_as_dns/replica0.ipa.test/var/log/ipareplica-install.log.gz but I see it in many places.


Ok, corresponding part from the access log on IPA server:

[15/Mar/2024:13:16:55.968939569 +0000] conn=80 fd=129 slot=129 connection from 192.168.121.21 to 192.168.121.21
[15/Mar/2024:13:16:55.970013390 +0000] conn=80 op=0 BIND dn="cn=Directory Manager" method=128 version=3
[15/Mar/2024:13:16:55.984424313 +0000] conn=80 op=0 RESULT err=0 tag=97 nentries=0 wtime=0.000039349 optime=0.014426124 etime=0.014461867 dn="cn=directory manager"
[15/Mar/2024:13:16:56.008708038 +0000] conn=80 op=1 ADD dn="uid=CA-master.ipa.test-8443,ou=People,o=ipaca"
[15/Mar/2024:13:16:56.013114762 +0000] conn=80 op=1 RESULT err=0 tag=105 nentries=0 wtime=0.000152248 optime=0.004412229 etime=0.004562299
[15/Mar/2024:13:16:56.016801553 +0000] conn=80 op=2 UNBIND
[15/Mar/2024:13:16:56.017322091 +0000] conn=80 op=2 fd=129 Disconnect - Cleanly Closed Connection - U1
[15/Mar/2024:13:22:55.457451475 +0000] conn=80 fd=236 slot=236 SSL connection from 192.168.121.173 to 192.168.121.21
[15/Mar/2024:13:22:55.463160564 +0000] conn=80 TLS1.3 128-bit AES-GCM
[15/Mar/2024:13:22:55.464616406 +0000] conn=80 op=0 BIND dn="" method=sasl version=3 mech=GSSAPI
[15/Mar/2024:13:22:55.468273106 +0000] conn=80 op=0 RESULT err=14 tag=97 nentries=0 wtime=0.005664183 optime=0.003662746 etime=0.009325755, SASL bind in progress
[15/Mar/2024:13:22:55.469116178 +0000] conn=80 op=1 BIND dn="" method=sasl version=3 mech=GSSAPI
[15/Mar/2024:13:22:55.471568090 +0000] conn=80 op=1 RESULT err=14 tag=97 nentries=0 wtime=0.000049287 optime=0.002455740 etime=0.002503425, SASL bind in progress
[15/Mar/2024:13:22:55.471949539 +0000] conn=80 op=2 BIND dn="" method=sasl version=3 mech=GSSAPI
[15/Mar/2024:13:22:55.473456667 +0000] conn=80 op=2 RESULT err=0 tag=97 nentries=0 wtime=0.000047666 optime=0.001509975 etime=0.001556467 dn="fqdn=replica0.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test"
....
[15/Mar/2024:13:23:37.100542078 +0000] conn=80 op=30 SRCH base="idnsname=replica0,idnsname=ipa.test.,cn=dns,dc=ipa,dc=test" scope=0 filter="(objectClass=*)" attrs="URIRecord LocRecord mXRecord cNAMERecord dSRecord HIPRecord SPFRecord APLRecord pTRRecord tXTRecord mInfoRecord DLVRecord aRecord mDRecord RPRecord SigRecord sRVRecord nXTRecord nAPTRRecord sSHFPRecord TLSARecord dNameRecord aAAARecord certRecord IPSECKEYRecord aFSDBRecord kXRecord DHCIDRecord KeyRecord rRSIGRecord nSRecord hInfoRecord nSECRecord a6Record"
[15/Mar/2024:13:23:37.101174149 +0000] conn=80 op=30 RESULT err=0 tag=101 nentries=0 wtime=0.001034587 optime=0.000664431 etime=0.001697553
[15/Mar/2024:13:23:37.103311593 +0000] conn=80 op=31 ADD dn="idnsname=replica0,idnsname=ipa.test.,cn=dns,dc=ipa,dc=test"
[15/Mar/2024:13:23:37.105451516 +0000] conn=80 op=31 RESULT err=50 tag=105 nentries=0 wtime=0.001750181 optime=0.002143104 etime=0.003892028
[15/Mar/2024:13:23:37.107724492 +0000] conn=80 op=32 UNBIND
[15/Mar/2024:13:23:37.108041001 +0000] conn=80 op=32 fd=236 Disconnect - Cleanly Closed Connection - U1

so this is replica0 host object not being able to add replica0 DNS record for itself. We probably have no access rights for that, even though we would have ones via dynamic DNS update since the default GSS-TSIG ACL allows host to add its own name.

Metadata