我是靠谱客的博主 自信老虎,最近开发中收集的这篇文章主要介绍freeipa(5)文件和日志位置,觉得挺不错的,现在分享给大家,希望可以做个参考。

概述

Table 18.1. FreeIPA Server Configuration Files and Directories
Directory or FileDescription
Server Configuration
/etc/ipaThe main FreeIPA configuration directory.
/etc/ipa/default.confThe primary configuration file for FreeIPA.
/etc/ipa/ca.crtThe CA certificate issued by the FreeIPA server's CA.
~/.ipa/A user-specific FreeIPA directory that is created on the local system in the system user's home directory the first time the user runs a FreeIPA command.
FreeIPA Logs
~/.ipa/log/cli.logThe log file for all XML-RPC calls and responses by the FreeIPA command-line tools. This is created in the home directory for the system user who runs the tools, who may have a different name than the FreeIPA user.
/var/log/ipaclient-install.logThe installation log for the client service.
/var/log/ipaserver-install.logThe installation log for the FreeIPA server.
System Services
/etc/rc.d/init.d/ipaThe FreeIPA server init script.
/etc/rc.d/init.d/ipa_kpasswdThe init script for the FreeIPA control daemon for Kerberos passwords.
/var/run/ipa_kpasswd.pidThe PID file for the Kerberos password daemon used by the FreeIPA service.
Web UI
/etc/ipa/htmlA symlink directory in the main configuration directory for the HTML files used by the FreeIPA web UI.
/etc/httpd/conf.d/ipa.conf
/etc/httpd/conf.d/ipa-rewrite.conf
The configuration files used by the Apache host for the web UI application.
/etc/httpd/conf/ipa.keytabThe keytab file used by the web UI service.
/usr/share/ipaThe main directory for all of the HTML files, scripts, and stylesheets used by the web UI.
/usr/share/ipa/ipa-rewrite.conf
/usr/share/ipa/ipa.conf
The configuration files used by the Apache host for the web UI application.
/usr/share/ipa/updatesContains any updated files, schema, and other elements for FreeIPA.
/usr/share/ipa/htmlContains the HTML files, JavaScript files, and stylesheets used by the web UI.
/usr/share/ipa/ipaclientContains the JavaScript files used to access Firefox's autoconfiguration feature and set up the Firefox browser to work in the FreeIPA Kerberos realm.
/usr/share/ipa/migrationContains HTML pages, stylesheets, and Python scripts used for running the FreeIPA server in migration mode.
/usr/share/ipa/uiContains all of the scripts used by the UI to perform FreeIPA operations.
/var/log/httpdThe log files for the Apache web server.
Kerberos
/etc/krb5.confThe Kerberos service configuration file.
SSSD
/etc/sssd/sssd.api.d/sssd-ipa.confThe configuration file used to identify the FreeIPA server, FreeIPA Directory Server, and other FreeIPA services used by SSSD.
/var/log/sssdThe log files for SSSD.
389 Directory Server
/var/lib/dirsrv/slapd-REALM_NAMEAll of the schema, configuration, and database files associated with the Directory Server instance used by the FreeIPA server.
/var/log/dirsrv/slapd-REALM_NAMELog files associated with the Directory Server instance used by the FreeIPA server.
Dogtag Certificate System
/etc/pki-caThe main directory for the FreeIPA CA instance.
/etc/pki-ca/conf/CS.cfgThe main configuration file for the FreeIPA CA instance.
/var/lib/dirsrv/slapd-PKI-IPA/All of the schema, configuration, and database files associated with the Directory Server instance used by the FreeIPA CA.
/var/log/dirsrv/slapd-PKI-IPA/Log files associated with the Directory Server instance used by the FreeIPA CA.
Cache Files
/var/cache/ipaCache files for the FreeIPA server and the FreeIPA Kerberos password daemon.
System Backups
/var/lib/ipa/sysrestoreContains backups of all of the system files and scripts that were reconfigured when the FreeIPA server was installed. These include the original .conf files for NSS, Kerberos (both krb5.conf and kdc.conf), and NTP.
/var/lib/ipa-client/sysrestoreContains backups of all of the system files and scripts that were reconfigured when the FreeIPA client was installed. Commonly, this is the sssd.conf file for SSSD authentication services.


Table 18.2. FreeIPA Log Files
ServiceLog FileDescriptionAdditional Information
FreeIPA server/var/log/ipaserver-install.logServer installation log 
FreeIPA server~/.ipa/log/cli.logCommand-line tool log 
FreeIPA client/var/log/ipaclient-install.logClient installation log 
Apache server
/var/log/httpd/access
/var/log/httpd/error
These are standard access and error logs for Apache servers. Both the web UI and the XML-RPC command-line interface use Apache, so some FreeIPA-specific messages will be recorded in the error log along with the Apache messages.Apache log chapter
Dogtag Certificate System/var/log/pki-ca-install.logThe installation log for the FreeIPA CA. 
Dogtag Certificate System
/var/log/pki-ca/debug
/var/log/pki-ca/system
/var/log/pki-ca/transactions
/var/log/pki-ca/signedAudit
These logs mainly relate to certificate operations. In FreeIPA, this is used for service principals, hosts, and other entities which use certificates.Logging chapter
389 Directory Server
/var/log/dirsrv/slapd-REALM/access
/var/log/dirsrv/slapd-REALM/audit
/var/log/dirsrv/slapd-REALM/errors
The access and error logs both contain detailed information about attempted access and operations for the domain Directory Server instance. The error log setting can be changed to provide very detailed output.The access log is buffered, so the server only writes to the log every 30 seconds, by default.
  • Monitoring servers and databases
  • Log entries explained
389 Directory Server
/var/log/dirsrv/slapd-REALM/access
/var/log/dirsrv/slapd-REALM/audit
/var/log/dirsrv/slapd-REALM/errors
This directory server instance is used by the FreeIPA CA to store certificate information. Most operational data here will be related to server-replica interactions.The access log is buffered, so the server only writes to the log every 30 seconds, by default.
  • Monitoring servers and databases
  • Log entries explained
Kerberos/var/log/krb5libs.logThis is the primary log file for Kerberos connections.This location is configured in the krb5.conf file, so it could be different on some systems.
Kerberos/var/log/krb5kdc.logThis is the primary log file for the Kerberos KDC server.This location is configured in the krb5.conf file, so it could be different on some systems.
Kerberos/var/log/kadmind.logThis is the primary log file for the Kerberos administration server.This location is configured in the krb5.conf file, so it could be different on some systems.
DNS/var/log/messagesDNS error messages are included with other system messages.DNS logging is not enabled by default. DNS logging is enabled by running the querylog command:
/usr/sbin/rndc querylog

This begins writing log messages to the system's /var/log/messages file. To turn off logging, run the querylog command again.

最后

以上就是自信老虎为你收集整理的freeipa(5)文件和日志位置的全部内容,希望文章能够帮你解决freeipa(5)文件和日志位置所遇到的程序开发问题。

如果觉得靠谱客网站的内容还不错,欢迎将靠谱客网站推荐给程序员好友。

本图文内容来源于网友提供,作为学习参考使用,或来自网络收集整理,版权属于原作者所有。
点赞(65)

评论列表共有 0 条评论

立即
投稿
返回
顶部