Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.
Bug 2117540 - [abrt] freeipa-server-dns: run(): ipautil.py:599:run:ipapython.ipautil.CalledProcessError: CalledProcessError(Command ['/usr/sbin/dnssec-keyfromlabel', '-E', 'pkcs11', '-K', '/var/named/dyndb-ldap/ipa/master/lan.dojoao.pt/tmpfeikbgnb', '-a', ...
Summary: [abrt] freeipa-server-dns: run(): ipautil.py:599:run:ipapython.ipautil.Called...
Keywords:
Status: CLOSED DUPLICATE of bug 2115865
Alias: None
Product: Fedora
Classification: Fedora
Component: freeipa
Version: 36
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: IPA Maintainers
QA Contact: Fedora Extras Quality Assurance
URL: https://retrace.fedoraproject.org/faf...
Whiteboard: abrt_hash:a3eae4b2a3a7fc7d9a6cf9c99d5...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-08-11 09:33 UTC by João Rodrigues
Modified: 2022-08-11 09:42 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-08-11 09:42:03 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: backtrace (deleted)
2022-08-11 09:33 UTC, João Rodrigues
no flags Details
File: cpuinfo (deleted)
2022-08-11 09:33 UTC, João Rodrigues
no flags Details
File: environ (deleted)
2022-08-11 09:33 UTC, João Rodrigues
no flags Details
File: mountinfo (deleted)
2022-08-11 09:33 UTC, João Rodrigues
no flags Details
File: namespaces (deleted)
2022-08-11 09:33 UTC, João Rodrigues
no flags Details
File: open_fds (deleted)
2022-08-11 09:33 UTC, João Rodrigues
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FREEIPA-8649 0 None None None 2022-08-11 09:36:26 UTC

Description João Rodrigues 2022-08-11 09:33:12 UTC
Description of problem:
Noticed this in my freeipa's dc log. It tries to run every minute or so and it fails

Version-Release number of selected component:
freeipa-server-dns-4.9.10-3.fc36

Additional info:
reporter:       libreport-2.17.1
cgroup:         0::/system.slice/ipa-dnskeysyncd.service
cmdline:        /usr/bin/python3 -I /usr/libexec/ipa/ipa-dnskeysyncd
crash_function: run
exception_type: ipapython.ipautil.CalledProcessError
executable:     /usr/libexec/ipa/ipa-dnskeysyncd
interpreter:    python3-3.10.6-1.fc36.x86_64
kernel:         5.18.16-200.fc36.x86_64
runlevel:       N 3
type:           Python3
uid:            996

Truncated backtrace:
#1 [/usr/lib/python3.10/site-packages/ipapython/ipautil.py:599] run
#2 [/usr/lib/python3.10/site-packages/ipaserver/dnssec/bindmgr.py:146] install_key
#3 [/usr/lib/python3.10/site-packages/ipaserver/dnssec/bindmgr.py:205] sync_zone
#4 [/usr/lib/python3.10/site-packages/ipaserver/dnssec/bindmgr.py:232] sync
#5 [/usr/lib/python3.10/site-packages/ipaserver/dnssec/keysyncer.py:128] syncrepl_refreshdone
#6 [/usr/lib64/python3.10/site-packages/ldap/syncrepl.py:464] syncrepl_poll
#7 [/usr/libexec/ipa/ipa-dnskeysyncd:130] <module>

Comment 1 João Rodrigues 2022-08-11 09:33:15 UTC
Created attachment 1904890 [details]
File: backtrace

Comment 2 João Rodrigues 2022-08-11 09:33:16 UTC
Created attachment 1904891 [details]
File: cpuinfo

Comment 3 João Rodrigues 2022-08-11 09:33:17 UTC
Created attachment 1904892 [details]
File: environ

Comment 4 João Rodrigues 2022-08-11 09:33:18 UTC
Created attachment 1904893 [details]
File: mountinfo

Comment 5 João Rodrigues 2022-08-11 09:33:19 UTC
Created attachment 1904894 [details]
File: namespaces

Comment 6 João Rodrigues 2022-08-11 09:33:20 UTC
Created attachment 1904895 [details]
File: open_fds

Comment 7 Florence Blanc-Renaud 2022-08-11 09:42:03 UTC
Hi,
thanks for your BZ report.
Based on the journal backtrace (dnssec-keyfromlabel: warning: ENGINE_load_private_key failed (not found)\ndnssec-keyfromlabel: fatal: failed to get key <domain removed>/RSASHA256: not found\n'), it can be closed as a duplicate of BZ #2115865.

There is already an update of openssl-pkcs11 (FEDORA-2022-2f6e9a0b6c has been submitted as an update to Fedora 36. https://bodhi.fedoraproject.org/updates/FEDORA-2022-2f6e9a0b6c) that contains a fix. Can you try to update and confirm it properly solves your issue?

*** This bug has been marked as a duplicate of bug 2115865 ***


Note You need to log in before you can comment on or make changes to this bug.