Hello Alfred,
If it is IPA deployment I doubt that you hit [1] because it only applies on read-only replica (hub/consumer). Also this bug is fixed in the version you are running.
The consumer (redactedauth0003.redacted.com) fails to apply a replicated MOD targeting the admin group. It is not clear if the failure occurs at changelog update or RUV update. It is looking it is a permanent failure so you may enable replication debug log in case it gives more details why it is failing.
regards
thierry
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1574602
Forwarding to 389-users@xxxxxxxxxxxxxxxxxxxxxxx as they may have more inputs.
On Wed, Jun 16, 2021 at 11:31 PM Alfred Victor via FreeIPA-users <freeipa-users@xxxxxxxxxxxxxxxxxxxxxx> wrote:
Hi FreeIPA,_______________________________________________
We have some replication messages in our slapd errors log which look very like the ones discussed here:
https://bugzilla.redhat.com/show_bug.cgi?id=1574602
I took a look and we do have the MemberOf plugin, but our version of 389-ds newer:
389-ds-base-1.3.10.2-10.el7_9.x86_64
Hoping someone might have a suggestion for what we might do to get rid of these log messages, or what the root cause may be/impact? They've been going since at least a couple of weeks ago:
[15/Jun/2021:18:57:26.362094959 -0500] - WARN - NSMMReplicationPlugin - repl5_inc_update_from_op_result - agmt="cn=redactedauth0001.redacted.com-to-redactedauth0003.redacted.com" (redactedauth0003:389): Consumer failed to replay change (uniqueid d5896001-39a111eb-8868efc8-91dc0b98, CSN 60c93bc2000400250000): Operations error (1). Will retry later.I looked for this same uniqueid (they are ALL the same uniqueID) and found this which is interesting and references a specific cn and "optype":[03/Jun/2021:15:45:43.332068775 -0500] - ERR - NSMMReplicationPlugin - write_changelog_and_ruv - Can't add a change for cn=admin,cn=groups,cn=accounts,dc=redacted,dc=com (uniqid: d5896001-39a111eb-8868efc8-91dc0b98, optype: 8) to changelog csn 60b93f93005200230000Alfred
FreeIPA-users mailing list -- freeipa-users@xxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to freeipa-users-leave@xxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedorahosted.org/archives/list/freeipa-users@xxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure
_______________________________________________ FreeIPA-users mailing list -- freeipa-users@xxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to freeipa-users-leave@xxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/freeipa-users@xxxxxxxxxxxxxxxxxxxxxx Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure
_______________________________________________ 389-users mailing list -- 389-users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to 389-users-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/389-users@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure