Posts

Deploying ESXi with Satellite 6

Deploy the files to the Satellite server Download the latest ISO from VMware (e.g. VMware-ESXi-5.5U2-RollupISO2.iso). Transfer to the satellite server Run some code # mount -o loop VMware-ESXi-5.5U2-RollupISO2.iso /mnt # mkdir /var/lib/tftpboot/boot/esxi55u2 # cd /mnt # cp -a * /var/lib/tftpboot/boot/esxi55u2 # cd /var/lib/tftpboot/boot/esxi55u2 # sed -i 's#/#/boot/esxi55u2/#g' boot.cfg # cd .. # restorecon -R esxi55u2 Create the Operating System inside Satellite Hosts -> Operating Systems Click New Operating System Operating System Name: ESXi Major version: 5 Minor version: 5 Description: ESXi 5.5U2 OS Family: Red Hat Arch: x86_64 Partition Table Kickstart Default Installation Media Any Mirror – Can create a esxi mirror if desired. Hosts -> Provisioning Templates Click New Template Provisioning Template Name: ESXi OCP PXELinux SERIAL 0 115200n8 DEFAULT esxi5.serial PROMPT 0 MENU TITLE PXE Boot LABEL esxi5.serial MENU LA...

Katello Capsule sync fails with error "401 - Authentication with username admin failed: invalid oauth credentials"

This issue occurs when there is a time difference in Satellite and Capsule server. Ensure that both the Satellite server and Capsule server is synced with the ntp or cronyd. Once the time is in sync, re-run the capsule-installer command to configure capsule server.  Diagnostic -Checking /var/log/messages goferd make  a clear error about authethication failed Feb 11 06:00:32 awscapsule01 goferd: [ERROR][worker-0] pulp.agent.lib.dispatcher:112 - PermissionsException: RequestException: GET request on /pulp/api/v2/consumers/add48221-f2d7-4bbe-b5ee-0eef65c24774/bindings/Centos-6/ failed with 401 - Authentication with username admin failed: invalid oauth credentials. Feb 11 06:00:32 awscapsule01 goferd: [INFO][worker-0] gofer.agent.rmi:128 - sn=76004451-4fc4-47d2-9862-29beb1d72e92 processed in: 2.181 (seconds)

How remove packages from custom repos in Katello

First find out the UUID of the package you will delete: Katello[~] # hammer package list --organization-label=rh --product=testrepo -------------------------------------|------------------------------------------------------ ID | FILENAME -------------------------------------|------------------------------------------------------ ab214fca-4a00-4275-b019-81d557b4e117 |test.rpm -------------------------------------|------------------------------------------------------ To obtain the ID of repository where the package is located, run the following command: satellite [~] # hammer repository list --organization-label=rh --product=testrepo ---|----------|----------|--------------|---- ID | NAME | PRODUCT | CONTENT TYPE | URL ---|----------|----------|--------------|---- 1 | test | test | yum | ---|----------|----------|--------------|---- Remove the package from the custom repo...

Could not parse for environment production: invalid byte sequence in UTF-8 at /root/celery.pp:1 (Puppet::Error) on Satellite 6

 The following error appear when try to generate a capsule certificate #capsule-certs-generate --capsule-fqdn capsule01.test.internal --certs-tar /root/capsule01.test.internal-certs.tar # /usr/share/ruby/vendor_ruby/puppet/parser/parser_support.rb:175:in `rescue in parse': Could not parse for environment production: invalid byte sequence in UTF-8 at /root/celery.pp:1 (Puppet::Error) from /usr/share/ruby/vendor_ruby/puppet/parser/parser_support.rb:166:in `parse' from /usr/share/ruby/vendor_ruby/puppet/node/environment.rb:536:in `block in perform_initial_import' from /usr/share/ruby/vendor_ruby/puppet/node/environment.rb:534:in `map' from /usr/share/ruby/vendor_ruby/puppet/node/environment.rb:534:in `perform_initial_import' from /usr/share/ruby/vendor_ruby/puppet/node/environment.rb:255:in `known_resource_types' from /usr/share/ruby/vendor_ruby/puppet/resource/type_collection_helper.rb:5:in `known_resource_types...

How to remove a puppet module on Katello or Satellite 6

1. -Enter in hammer shell with the following command #hammer -u admin -p <password> shell 2. -First we need to get our Organization ID with the following command #hammer> organization list ---|----------|----------|------------ ID | NAME     | LABEL    | DESCRIPTION ---|------------|------------|------------ 1  | Example | Example | ---|------------|-------------|------------ 3.- We check the repositories to get the id of our puppet repository #hammer> repository list --organization-id 1 ---|---------------------------|------------------------|------------------------|-------------------------- ID | NAME                      | PRODUCT            | CONTENT TYPE  | URL ---|---------------------------|------------------------|------------------------|--------------------...

Setup dynamc DNS updates with Active Directory DNS to be used by Smart Proxy of Katello/Foreman

Both BIND as configured in FreeIPA and Microsoft AD DNS servers can accept DNS updates using GSS-TSIG authentication. This uses Kerberos principals to authenticate to the DNS server. Under Microsoft AD, this is known as "Secure Dynamic Update". Pre-requisites     Kerberos principal in the realm/domain that Smart Proxy can use     Kerberos keytab for the above principal Setup krb5.conf cat > /etc/krb5.conf << "EOF" [logging]  default = FILE:/var/log/krb5libs.log  kdc = FILE:/var/log/krb5kdc.log  admin_server = FILE:/var/log/kadmind.log [libdefaults]  default_realm = EXAMPLE.COM  dns_lookup_realm = true  dns_lookup_kdc = true  ticket_lifetime = 24h  renew_lifetime = 7d  forwardable = true [realms]  EXAMPLE.COM = {   kdc = dc01.example.com   admin_server = dc01.example.com  } [domain_realm]  example.com = EXAMPLE.COM  .example.com = EXAMPLE.COM...

Sync Repos finish with warning hostname does not match the server certificate

This is happening because the following: Actions::Katello::Repository::ErrataMail Input: {"repo"=>4, "last_updated"=>"2015-10-17 02:20:18 +1300", "locale"=>"en"} Output: {} Exception: OpenSSL::SSL::SSLError: hostname does not match the server certificate   As we can see the sync of repos is failed because the errata mail can't be send it to resolve this issue we need to configure our email.yml   # cat /etc/foreman/email.yaml # Outgoing email settings production: delivery_method: :smtp smtp_settings: address: smtp.example.com port: 25 enable_starttls_auto: false << add this to avoid the connection via tls to  the mail server if you don't needed.