Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1262315
Description of problem: Winsync replication fails with error unexpected error: {'desc': 'Object class violation'} Version-Release number of selected component (if applicable): # rpm -q ipa-server ipa-server-4.2.0-9.el7.x86_64 How reproducible: Always Steps to Reproduce: 1. Setup winync replication 2. 3. Actual results: :: [ BEGIN ] :: Creating Winsync Agreement with valid cert :: actually running 'ipa-replica-manage connect --winsync --passsync=password --cacert=/tmp/tmp.GqgBmxLgKR/ADcert.cer squab.adrelm.com --binddn "CN=Administrator,CN=Users,DC=adrelm,DC=com" --bindpw Secret123 -v -p Secret123 > /tmp/tmp.GqgBmxLgKR/tmpout.ipa_winsync_0003.out 2>&1' :: [ FAIL ] :: Creating Winsync Agreement with valid cert (Expected 0, got 1) ipa: INFO: AD Suffix is: DC=adrelm,DC=com Added CA certificate /tmp/tmp.GqgBmxLgKR/ADcert.cer to certificate database for vm-idm-008.syncwin.test The user for the Windows PassSync service is uid=passsync,cn=sysaccounts,cn=etc,dc=syncwin,dc=test Adding Windows PassSync system account unexpected error: {'desc': 'Object class violation'} [root@vm-idm-008 sgoveas]# tail -100 /var/log/dirsrv/slapd-SYNCWIN-TEST/errors [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_ECDH_RSA_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_ECDH_RSA_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_RSA_WITH_AES_256_GCM_SHA384: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_RSA_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_RSA_WITH_AES_256_CBC_SHA256: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_RSA_WITH_CAMELLIA_256_CBC_SHA: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_RSA_WITH_AES_128_GCM_SHA256: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_RSA_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_RSA_WITH_AES_128_CBC_SHA256: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_RSA_WITH_CAMELLIA_128_CBC_SHA: enabled [11/Sep/2015:16:07:30 +051800] - SSL alert: TLS_RSA_WITH_SEED_CBC_SHA: enabled [11/Sep/2015:16:07:30 +051800] SSL Initialization - Configured SSL version range: min: TLS1.0, max: TLS1.2 [11/Sep/2015:16:07:30 +051800] - 389-Directory/1.3.4.0 B2015.247.1833 starting up [11/Sep/2015:16:07:30 +051800] schema-compat-plugin - warning: no entries set up under cn=computers, cn=compat,dc=syncwin,dc=test [11/Sep/2015:16:07:30 +051800] schema-compat-plugin - warning: no entries set up under cn=ng, cn=compat,dc=syncwin,dc=test [11/Sep/2015:16:07:30 +051800] schema-compat-plugin - warning: no entries set up under ou=sudoers,dc=syncwin,dc=test [11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=groups,cn=compat,dc=syncwin,dc=test does not exist [11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=computers,cn=compat,dc=syncwin,dc=test does not exist [11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=ng,cn=compat,dc=syncwin,dc=test does not exist [11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target ou=sudoers,dc=syncwin,dc=test does not exist [11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=users,cn=compat,dc=syncwin,dc=test does not exist [11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=ad,cn=etc,dc=syncwin,dc=test does not exist [11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=syncwin,dc=test does not exist [11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=syncwin,dc=test does not exist [11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=automember rebuild membership,cn=tasks,cn=config does not exist [11/Sep/2015:16:07:30 +051800] - Skipping CoS Definition cn=Password Policy,cn=accounts,dc=syncwin,dc=test--no CoS Templates found, which should be added before the CoS Definition. [11/Sep/2015:16:07:30 +051800] - slapd started. Listening on All Interfaces port 389 for LDAP requests [11/Sep/2015:16:07:30 +051800] - Listening on All Interfaces port 636 for LDAPS requests [11/Sep/2015:16:07:30 +051800] - Listening on /var/run/slapd-SYNCWIN-TEST.socket for LDAPI requests [11/Sep/2015:16:44:19 +051800] - slapd shutting down - signaling operation threads - op stack size 2 max work q size 1 max work q stack size 1 [11/Sep/2015:16:44:19 +051800] - slapd shutting down - waiting for 27 threads to terminate [11/Sep/2015:16:44:19 +051800] - slapd shutting down - closing down internal subsystems and plugins [11/Sep/2015:16:44:20 +051800] - Waiting for 4 database threads to stop [11/Sep/2015:16:44:21 +051800] - All database threads now stopped [11/Sep/2015:16:44:21 +051800] - slapd shutting down - freed 1 work q stack objects - freed 4 op stack objects [11/Sep/2015:16:44:21 +051800] - slapd stopped. [11/Sep/2015:16:44:22 +051800] - SSL alert: Configured NSS Ciphers [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_DSS_WITH_AES_256_GCM_SHA384: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_RSA_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_DSS_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_DSS_WITH_AES_256_CBC_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_DSS_WITH_AES_128_GCM_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_RSA_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_DSS_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_DSS_WITH_AES_128_CBC_SHA256: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDH_RSA_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_ECDH_RSA_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_RSA_WITH_AES_256_GCM_SHA384: enabled [11/Sep/2015:16:44:22 +051800] - SSL alert: TLS_RSA_WITH_AES_256_CBC_SHA: enabled [11/Sep/2015:16:44:23 +051800] - SSL alert: TLS_RSA_WITH_AES_256_CBC_SHA256: enabled [11/Sep/2015:16:44:23 +051800] - SSL alert: TLS_RSA_WITH_CAMELLIA_256_CBC_SHA: enabled [11/Sep/2015:16:44:23 +051800] - SSL alert: TLS_RSA_WITH_AES_128_GCM_SHA256: enabled [11/Sep/2015:16:44:23 +051800] - SSL alert: TLS_RSA_WITH_AES_128_CBC_SHA: enabled [11/Sep/2015:16:44:23 +051800] - SSL alert: TLS_RSA_WITH_AES_128_CBC_SHA256: enabled [11/Sep/2015:16:44:23 +051800] - SSL alert: TLS_RSA_WITH_CAMELLIA_128_CBC_SHA: enabled [11/Sep/2015:16:44:23 +051800] - SSL alert: TLS_RSA_WITH_SEED_CBC_SHA: enabled [11/Sep/2015:16:44:23 +051800] SSL Initialization - Configured SSL version range: min: TLS1.0, max: TLS1.2 [11/Sep/2015:16:44:23 +051800] - 389-Directory/1.3.4.0 B2015.247.1833 starting up [11/Sep/2015:16:44:23 +051800] schema-compat-plugin - warning: no entries set up under cn=computers, cn=compat,dc=syncwin,dc=test [11/Sep/2015:16:44:23 +051800] schema-compat-plugin - warning: no entries set up under cn=ng, cn=compat,dc=syncwin,dc=test [11/Sep/2015:16:44:23 +051800] schema-compat-plugin - warning: no entries set up under ou=sudoers,dc=syncwin,dc=test [11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=groups,cn=compat,dc=syncwin,dc=test does not exist [11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=computers,cn=compat,dc=syncwin,dc=test does not exist [11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=ng,cn=compat,dc=syncwin,dc=test does not exist [11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target ou=sudoers,dc=syncwin,dc=test does not exist [11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=users,cn=compat,dc=syncwin,dc=test does not exist [11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=ad,cn=etc,dc=syncwin,dc=test does not exist [11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=syncwin,dc=test does not exist [11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=syncwin,dc=test does not exist [11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=automember rebuild membership,cn=tasks,cn=config does not exist [11/Sep/2015:16:44:23 +051800] - Skipping CoS Definition cn=Password Policy,cn=accounts,dc=syncwin,dc=test--no CoS Templates found, which should be added before the CoS Definition. [11/Sep/2015:16:44:23 +051800] - slapd started. Listening on All Interfaces port 389 for LDAP requests [11/Sep/2015:16:44:23 +051800] - Listening on All Interfaces port 636 for LDAPS requests [11/Sep/2015:16:44:23 +051800] - Listening on /var/run/slapd-SYNCWIN-TEST.socket for LDAPI requests [11/Sep/2015:16:44:24 +051800] - Entry "uid=passsync,cn=sysaccounts,cn=etc,dc=syncwin,dc=test" -- attribute "memberOf" not allowed [11/Sep/2015:16:44:24 +051800] memberof-plugin - memberof_postop_modify: failed to replace values in dn (cn=PassSync Service,cn=privileges,cn=pbac,dc=syncwin,dc=test). Error (65) Expected results: Winsync replication is establised Additional info:
The ticket was cloned just for tracking purposes.
ipa-4-2:
master:
Metadata Update from @pvoborni: - Issue assigned to someone - Issue set to the milestone: FreeIPA 4.2.2