In testing out the fix for Dogtag TRAC Ticket #816 - pki-tomcat cannot be started after installation of ipa replica with ca, I attempted to test configuration using the GUI panels via a Firefox browser.
Unfortunately, configuration was unable to proceed past the Database panel. Apparently, one must utilize values for the 'pki_clone_replication_master_port' as well as the 'pki_clone_replication_clone_port'.
Per the 'pki_default.cfg' man page, I utilized the following values for the 'Replication Details' section of the Database panel:
Master Replication Port: 389 Clone Replication Port: 389 Replication Security: x None o TLS o SSL
Unfortunately I was never able proceed past this panel.
The 'master' DS 'errors' log contained the message:
[26/Feb/2014:17:03:17 -0800] slapi_ldap_bind - Error: could not bind id [cn=Replication Manager cloneAgreement1-fedora20.example.com-pki-tomcat,ou=csusers,cn=config] authentication mechanism [SIMPLE]: error 32 (No such object) errno 0 (Success)
The clone 'error' log contained:
[26/Feb/2014:17:00:08 -0800] NSMMReplicationPlugin - agmt="cn=cloneAgreement1-fedora20.example.com-pki-tomcat" (dogtag19:389): The remote replica has a different database generation ID than the local database. You may have to reinitialize the remote replica, or the local replica.
As I tried this numerous times, I believe there were some log messages prior to these, so they may not be accurate. The other possibility is that this problem may be associated with the 389 TRAC Ticket #47721 - Schema Replication Issue.
[06/04/2014] - Moving to Milestone 10.2.1 due to schedule restrictions.
This is being resolved as 'wontfix' since we have decided to remove the GUI browser configuration panels interface. (per CS Meeting of 09/17/2014)
Metadata Update from @mharmsen: - Issue set to the milestone: 10.2.1
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/1438
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.