<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Wed, Dec 10, 2014 at 7:16 PM, Alon Bar-Lev <span dir="ltr">&lt;<a href="mailto:alonbl@redhat.com" target="_blank">alonbl@redhat.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><span class=""><br></span><span class=""><br>
<br>
</span>probably I some startup error at engine.log, can you please send me engine.log so I can see what&#39;s wrong?</blockquote><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
<span class=""><br>
&gt; BTW: I tried my IPA lookup just for trying.... and I&#39;m able to find all the<br>
&gt; users and also new users defined after migration to the new c7server.... ???<br>
&gt; <a href="https://drive.google.com/file/d/0BwoPbcrMv8mvbks2cmlhSmJjdnc/view?usp=sharing" target="_blank">https://drive.google.com/file/d/0BwoPbcrMv8mvbks2cmlhSmJjdnc/view?usp=sharing</a><br>
<br></span></blockquote><div><br></div><div>ok. done.</div><div>Here it is</div><div><a href="https://drive.google.com/file/d/0BwoPbcrMv8mvQWZ0R3lwX2RXTEU/view?usp=sharing">https://drive.google.com/file/d/0BwoPbcrMv8mvQWZ0R3lwX2RXTEU/view?usp=sharing</a><br></div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><span class="">
</span>so legacy is working now, right?<br>
<br>
&gt;<br>
&gt; Gianluca<br>
&gt;<br>
</blockquote></div><br></div><div class="gmail_extra">Yes, I can browse the IPA users and I can also login again with an IPA user with the same permissions he had before, connected with &quot;localdomain.local&quot; profile that is the legacy one</div><div class="gmail_extra">This afternoon when I posted the first question of this thread it didn&#39;t worked.</div><div class="gmail_extra">I don&#39;t know if oVirt makes a sort of broadcast related to the domain and so can find now the new IPA server transparently or the engine-config commands produced anything despite the errors they gave....</div><div class="gmail_extra"><br></div><div class="gmail_extra">In relation with the ldap instance  see this in engine.log just after engine last start after adding the aaa extension</div><div class="gmail_extra"><br></div><div class="gmail_extra"><div class="gmail_extra">2014-12-10 19:03:16,591 ERROR [org.ovirt.engineextensions.aaa.ldap.AuthzExtension] (MSC service thread 1-1)</div><div class="gmail_extra"> [ovirt-engine-extension-aaa-ldap.authz::ldap1-authz] Cannot initialize LDAP framework, deferring initializ</div><div class="gmail_extra">ation. Error: no such object</div><div class="gmail_extra">2014-12-10 19:03:16,592 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread</div><div class="gmail_extra">1-1) Extension &#39;ldap1-authz&#39; initialized</div><div class="gmail_extra">2014-12-10 19:03:16,596 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread</div><div class="gmail_extra">1-1) Initializing extension &#39;internal&#39;</div><div class="gmail_extra">2014-12-10 19:03:16,598 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread</div><div class="gmail_extra">1-1) Extension &#39;internal&#39; initialized</div><div class="gmail_extra">2014-12-10 19:03:16,598 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread</div><div class="gmail_extra">1-1) Initializing extension &#39;localdomain.local&#39;</div><div class="gmail_extra">2014-12-10 19:03:16,599 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread</div><div class="gmail_extra">1-1) Extension &#39;localdomain.local&#39; initialized</div><div class="gmail_extra">2014-12-10 19:03:16,599 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread</div><div class="gmail_extra">1-1) Start of enabled extensions list</div><div class="gmail_extra">2014-12-10 19:03:16,599 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread</div><div class="gmail_extra">1-1) Instance name: &#39;builtin-authn-localdomain.local&#39;, Extension name: &#39;Kerberos/Ldap Authn (Built-in)&#39;, Ve</div><div class="gmail_extra">rsion: &#39;N/A&#39;, Notes: &#39;&#39;, License: &#39;ASL 2.0&#39;, Home: &#39;<a href="http://www.ovirt.org">http://www.ovirt.org</a>&#39;, Author &#39;The oVirt Project&#39;, Buil</div><div class="gmail_extra">d interface Version: &#39;0&#39;,  File: &#39;N/A&#39;, Initialized: &#39;true&#39;</div><div><div>2014-12-10 19:03:16,603 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread</div><div>1-1) Instance name: &#39;ldap1-authn&#39;, Extension name: &#39;ovirt-engine-extension-aaa-ldap.authn&#39;, Version: &#39;1.0.0</div><div>&#39;, Notes: &#39;Display name: ovirt-engine-extension-aaa-ldap-1.0.0-1.el6&#39;, License: &#39;ASL 2.0&#39;, Home: &#39;<a href="http://www.ovirt.org">http://www.ovirt.org</a>&#39;, Author &#39;The oVirt Project&#39;, Build interface Version: &#39;0&#39;,  File: &#39;/etc/ovirt-engine/extensions.d/domain1-authn.properties&#39;, Initialized: &#39;true&#39;</div><div>2014-12-10 19:03:16,604 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread 1-1) Instance name: &#39;builtin-authn-internal&#39;, Extension name: &#39;Internal Authn (Built-in)&#39;, Version: &#39;N/A&#39;, Notes: &#39;&#39;, License: &#39;ASL 2.0&#39;, Home: &#39;<a href="http://www.ovirt.org">http://www.ovirt.org</a>&#39;, Author &#39;The oVirt Project&#39;, Build interface Version: &#39;0&#39;,  File: &#39;N/A&#39;, Initialized: &#39;true&#39;</div><div>2014-12-10 19:03:16,604 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread 1-1) Instance name: &#39;ldap1-authz&#39;, Extension name: &#39;ovirt-engine-extension-aaa-ldap.authz&#39;, Version: &#39;1.0.0&#39;, Notes: &#39;Display name: ovirt-engine-extension-aaa-ldap-1.0.0-1.el6&#39;, License: &#39;ASL 2.0&#39;, Home: &#39;<a href="http://www.ovirt.org">http://www.ovirt.org</a>&#39;, Author &#39;The oVirt Project&#39;, Build interface Version: &#39;0&#39;,  File: &#39;/etc/ovirt-engine/extensions.d/domain1-authz.properties&#39;, Initialized: &#39;true&#39;</div><div>2014-12-10 19:03:16,605 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread 1-1) Instance name: &#39;internal&#39;, Extension name: &#39;Internal Authz (Built-in)&#39;, Version: &#39;N/A&#39;, Notes: &#39;&#39;, License: &#39;ASL 2.0&#39;, Home: &#39;<a href="http://www.ovirt.org">http://www.ovirt.org</a>&#39;, Author &#39;The oVirt Project&#39;, Build interface Version: &#39;0&#39;,  File: &#39;N/A&#39;, Initialized: &#39;true&#39;</div><div>2014-12-10 19:03:16,606 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread 1-1) Instance name: &#39;localdomain.local&#39;, Extension name: &#39;Kerberos/Ldap Authz (Built-in)&#39;, Version: &#39;N/A&#39;, Notes: &#39;&#39;, License: &#39;ASL 2.0&#39;, Home: &#39;<a href="http://www.ovirt.org">http://www.ovirt.org</a>&#39;, Author &#39;The oVirt Project&#39;, Build interface Version: &#39;0&#39;,  File: &#39;N/A&#39;, Initialized: &#39;true&#39;</div><div>2014-12-10 19:03:16,609 INFO  [org.ovirt.engine.core.extensions.mgr.ExtensionsManager] (MSC service thread 1-1) End of enabled extensions list</div></div><div><br></div><div>and then no other ERROR messages, but you can check the whole log.</div><div><br></div></div><div class="gmail_extra"><br></div><div class="gmail_extra">Gianluca</div></div>