2020-02-29T07:51:43Z DEBUG Logging to /var/log/ipaserver-install.log 2020-02-29T07:51:43Z DEBUG ipa-server-install was invoked with arguments [] and options: {'unattended': False, 'ip_addresses': None, 'domain_name': None, 'realm_name': None, 'host_name': None, 'ca_cert_files': None, 'domain_level': None, 'setup_adtrust': False, 'setup_kra': False, 'setup_dns': False, 'idstart': None, 'idmax': None, 'no_hbac_allow': False, 'no_pkinit': False, 'no_ui_redirect': False, 'dirsrv_config_file': None, 'dirsrv_cert_files': None, 'http_cert_files': None, 'pkinit_cert_files': None, 'dirsrv_cert_name': None, 'http_cert_name': None, 'pkinit_cert_name': None, 'mkhomedir': False, 'ntp_servers': None, 'ntp_pool': None, 'no_ntp': False, 'force_ntpd': False, 'ssh_trust_dns': False, 'no_ssh': False, 'no_sshd': False, 'no_dns_sshfp': False, 'external_ca': False, 'external_ca_type': None, 'external_ca_profile': None, 'external_cert_files': None, 'subject_base': None, 'ca_subject': None, 'ca_signing_algorithm': None, 'pki_config_override': None, 'allow_zone_overlap': False, 'reverse_zones': None, 'no_reverse': False, 'auto_reverse': False, 'zonemgr': None, 'forwarders': None, 'no_forwarders': False, 'auto_forwarders': False, 'forward_policy': None, 'no_dnssec_validation': False, 'no_host_dns': False, 'enable_compat': False, 'netbios_name': None, 'no_msdcs': False, 'rid_base': None, 'secondary_rid_base': None, 'ignore_topology_disconnect': False, 'ignore_last_of_role': False, 'verbose': False, 'quiet': False, 'log_file': None, 'uninstall': False} 2020-02-29T07:51:43Z DEBUG IPA version 4.8.3-1.fc30 2020-02-29T07:51:43Z DEBUG Searching for an interface of IP address: ::1 2020-02-29T07:51:43Z DEBUG Testing local IP address: ::1/128 (interface: lo) 2020-02-29T07:51:43Z DEBUG Starting external process 2020-02-29T07:51:43Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-02-29T07:51:43Z DEBUG Process finished, return code=1 2020-02-29T07:51:43Z DEBUG stdout= 2020-02-29T07:51:43Z DEBUG stderr= 2020-02-29T07:51:43Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:51:43Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-02-29T07:51:43Z DEBUG httpd is not configured 2020-02-29T07:51:43Z DEBUG kadmin is not configured 2020-02-29T07:51:43Z DEBUG dirsrv is not configured 2020-02-29T07:51:43Z DEBUG pki-tomcatd is not configured 2020-02-29T07:51:43Z DEBUG install is not configured 2020-02-29T07:51:43Z DEBUG krb5kdc is not configured 2020-02-29T07:51:43Z DEBUG named is not configured 2020-02-29T07:51:43Z DEBUG filestore is tracking no files 2020-02-29T07:51:43Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2020-02-29T07:51:43Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-02-29T07:51:43Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:51:43Z DEBUG Starting external process 2020-02-29T07:51:43Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2020-02-29T07:51:43Z DEBUG Process finished, return code=1 2020-02-29T07:51:43Z DEBUG stdout= 2020-02-29T07:51:43Z DEBUG stderr=Failed to get unit file state for ntpd.service: No such file or directory 2020-02-29T07:51:43Z DEBUG Starting external process 2020-02-29T07:51:43Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2020-02-29T07:51:43Z DEBUG Process finished, return code=3 2020-02-29T07:51:43Z DEBUG stdout=inactive 2020-02-29T07:51:43Z DEBUG stderr= 2020-02-29T07:52:17Z DEBUG Check if vault-ca.mydomain.local is a primary hostname for localhost 2020-02-29T07:52:17Z DEBUG Primary hostname for localhost: vault-ca.mydomain.local 2020-02-29T07:52:17Z DEBUG Search DNS for vault-ca.mydomain.local 2020-02-29T07:52:17Z DEBUG Check if vault-ca.mydomain.local is not a CNAME 2020-02-29T07:52:17Z DEBUG Check reverse address of 10.137.0.31 2020-02-29T07:52:17Z DEBUG Found reverse name: vault-ca.mydomain.local 2020-02-29T07:52:17Z DEBUG will use host_name: vault-ca.mydomain.local 2020-02-29T07:52:21Z DEBUG read domain_name: mydomain.local 2020-02-29T07:52:23Z DEBUG read realm_name: MYDOMAIN.LOCAL 2020-02-29T07:52:42Z DEBUG Writing configuration file /etc/ipa/default.conf 2020-02-29T07:52:42Z DEBUG [global] host = vault-ca.mydomain.local basedn = dc=mydomain,dc=local realm = MYDOMAIN.LOCAL domain = mydomain.local xmlrpc_uri = https://vault-ca.mydomain.local/ipa/xml ldap_uri = ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket mode = production enable_ra = True ra_plugin = dogtag dogtag_version = 10 2020-02-29T07:52:42Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-02-29T07:52:42Z DEBUG importing plugin module ipaserver.plugins.aci 2020-02-29T07:52:42Z DEBUG importing plugin module ipaserver.plugins.automember 2020-02-29T07:52:42Z DEBUG importing plugin module ipaserver.plugins.automount 2020-02-29T07:52:42Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-02-29T07:52:42Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-02-29T07:52:42Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.batch 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.ca 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.cert 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.config 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.dns 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.group 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-02-29T07:52:43Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.host 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.internal 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.join 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.location 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.migration 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.misc 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.otp 2020-02-29T07:52:43Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.permission 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.ping 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-02-29T07:52:43Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.role 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.schema 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.server 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.service 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.session 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-02-29T07:52:43Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.topology 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.trust 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.user 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.vault 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-02-29T07:52:43Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-02-29T07:52:43Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-02-29T07:52:43Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-02-29T07:52:44Z DEBUG check_port_bindable: Checking IPv4/IPv6 dual stack and TCP 2020-02-29T07:52:44Z DEBUG check_port_bindable: bind success: 8443/TCP 2020-02-29T07:52:44Z DEBUG check_port_bindable: Checking IPv4/IPv6 dual stack and TCP 2020-02-29T07:52:44Z DEBUG check_port_bindable: bind success: 8080/TCP 2020-02-29T07:52:44Z DEBUG Name vault-ca.mydomain.local resolved to {UnsafeIPAddress('10.137.0.31')} 2020-02-29T07:52:44Z DEBUG Searching for an interface of IP address: 10.137.0.31 2020-02-29T07:52:44Z DEBUG Testing local IP address: 127.0.0.1/255.0.0.0 (interface: lo) 2020-02-29T07:52:44Z DEBUG Testing local IP address: 10.137.0.31/255.255.255.255 (interface: eth0) 2020-02-29T07:53:52Z DEBUG Starting external process 2020-02-29T07:53:52Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-02-29T07:53:52Z DEBUG Process finished, return code=1 2020-02-29T07:53:52Z DEBUG stdout= 2020-02-29T07:53:52Z DEBUG stderr= 2020-02-29T07:53:52Z DEBUG Created PKCS#11 module config '/etc/pkcs11/modules/softhsm2.module'. 2020-02-29T07:53:52Z DEBUG Starting external process 2020-02-29T07:53:52Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2020-02-29T07:53:52Z DEBUG Process finished, return code=1 2020-02-29T07:53:52Z DEBUG stdout= 2020-02-29T07:53:52Z DEBUG stderr=Failed to get unit file state for ntpd.service: No such file or directory 2020-02-29T07:53:52Z DEBUG Starting external process 2020-02-29T07:53:52Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2020-02-29T07:53:52Z DEBUG Process finished, return code=3 2020-02-29T07:53:52Z DEBUG stdout=inactive 2020-02-29T07:53:52Z DEBUG stderr= 2020-02-29T07:53:52Z DEBUG Search DNS for SRV record of _ntp._udp.None 2020-02-29T07:53:52Z DEBUG DNS record not found: NXDOMAIN 2020-02-29T07:53:52Z INFO Synchronizing time 2020-02-29T07:53:52Z WARNING No SRV records of NTP servers found and no NTP server or pool address was provided. 2020-02-29T07:53:52Z DEBUG Starting external process 2020-02-29T07:53:52Z DEBUG args=['/bin/systemctl', 'enable', 'chronyd.service'] 2020-02-29T07:53:53Z DEBUG Process finished, return code=0 2020-02-29T07:53:53Z DEBUG stdout= 2020-02-29T07:53:53Z DEBUG stderr= 2020-02-29T07:53:53Z DEBUG Starting external process 2020-02-29T07:53:53Z DEBUG args=['/bin/systemctl', 'restart', 'chronyd.service'] 2020-02-29T07:53:53Z DEBUG Process finished, return code=0 2020-02-29T07:53:53Z DEBUG stdout= 2020-02-29T07:53:53Z DEBUG stderr= 2020-02-29T07:53:53Z DEBUG Starting external process 2020-02-29T07:53:53Z DEBUG args=['/bin/systemctl', 'is-active', 'chronyd.service'] 2020-02-29T07:53:53Z DEBUG Process finished, return code=3 2020-02-29T07:53:53Z DEBUG stdout=inactive 2020-02-29T07:53:53Z DEBUG stderr= 2020-02-29T07:53:53Z DEBUG Restart of chronyd.service complete 2020-02-29T07:53:53Z INFO Attempting to sync time with chronyc. 2020-02-29T07:53:53Z DEBUG Starting external process 2020-02-29T07:53:53Z DEBUG args=['/usr/bin/chronyc', 'waitsync', '3', '-d'] 2020-02-29T07:54:13Z DEBUG Process finished, return code=1 2020-02-29T07:54:13Z DEBUG stdout=506 Cannot talk to daemon 506 Cannot talk to daemon 506 Cannot talk to daemon 2020-02-29T07:54:13Z DEBUG stderr= 2020-02-29T07:54:13Z WARNING Process chronyc waitsync failed to sync time! 2020-02-29T07:54:13Z WARNING Unable to sync time with chrony server, assuming the time is in sync. Please check that 123 UDP port is opened, and any time server is on network. 2020-02-29T07:54:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:54:13Z DEBUG Configuring directory server (dirsrv). Estimated time: 30 seconds 2020-02-29T07:54:13Z DEBUG [1/44]: creating directory server instance 2020-02-29T07:54:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:54:13Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:54:13Z DEBUG Running setup with verbose 2020-02-29T07:54:13Z DEBUG START: Starting installation... 2020-02-29T07:54:13Z DEBUG READY: Preparing installation for MYDOMAIN-LOCAL... 2020-02-29T07:54:13Z DEBUG PASSED: using config settings 999999999 2020-02-29T07:54:13Z DEBUG PASSED: user / group checking 2020-02-29T07:54:13Z DEBUG PASSED: prefix checking 2020-02-29T07:54:13Z DEBUG list instance not found in /etc/dirsrv/slapd-MYDOMAIN-LOCAL/dse.ldif: MYDOMAIN-LOCAL 2020-02-29T07:54:13Z DEBUG PASSED: instance checking 2020-02-29T07:54:19Z DEBUG INFO: temp root password set to tDqQWK4K.QOJRadsMUeXjDaYVJb7elXSWWjR9Pqyp9X55Tc7e8c2kWC0FeTKKerEs 2020-02-29T07:54:19Z DEBUG PASSED: root user checking 2020-02-29T07:54:19Z DEBUG PASSED: network avaliability checking 2020-02-29T07:54:19Z DEBUG READY: Beginning installation for MYDOMAIN-LOCAL... 2020-02-29T07:54:19Z DEBUG ACTION: Creating dse.ldif 2020-02-29T07:54:19Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-MYDOMAIN-LOCAL/bak 2020-02-29T07:54:19Z DEBUG ACTION: creating /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:54:19Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-MYDOMAIN-LOCAL/db 2020-02-29T07:54:19Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-MYDOMAIN-LOCAL/ldif 2020-02-29T07:54:19Z DEBUG ACTION: creating /var/lock/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:54:19Z DEBUG ACTION: creating /var/log/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:54:19Z DEBUG ACTION: creating /var/run/dirsrv 2020-02-29T07:54:19Z DEBUG CMD: systemctl enable dirsrv@MYDOMAIN-LOCAL ; STDOUT: ; STDERR: Created symlink /etc/systemd/system/multi-user.target.wants/dirsrv@MYDOMAIN-LOCAL.service → /usr/lib/systemd/system/dirsrv@.service. 2020-02-29T07:54:19Z DEBUG ACTION: Creating certificate database is /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:54:19Z DEBUG Allocate with None 2020-02-29T07:54:19Z DEBUG Allocate with vault-ca:389 2020-02-29T07:54:19Z DEBUG Allocate with vault-ca:389 2020-02-29T07:54:19Z DEBUG nss cmd: /usr/bin/certutil -N -d /etc/dirsrv/slapd-MYDOMAIN-LOCAL -f /etc/dirsrv/slapd-MYDOMAIN-LOCAL/pwdfile.txt 2020-02-29T07:54:24Z DEBUG nss output: 2020-02-29T07:54:24Z DEBUG nss cmd: /usr/bin/certutil -N -d /etc/dirsrv/ssca/ -f /etc/dirsrv/ssca//pwdfile.txt 2020-02-29T07:54:30Z DEBUG nss output: 2020-02-29T07:54:31Z DEBUG nss cmd: /usr/bin/certutil -S -n Self-Signed-CA -s CN=ssca.389ds.example.com,O=testing,L=389ds,ST=Queensland,C=AU -x -g 4096 -t CT,, -v 24 --keyUsage certSigning -d /etc/dirsrv/ssca/ -z /etc/dirsrv/ssca//noise.txt -f /etc/dirsrv/ssca//pwdfile.txt 2020-02-29T07:54:38Z DEBUG nss output: Generating key. This may take a few moments... 2020-02-29T07:54:38Z DEBUG nss cmd: /usr/bin/certutil -L -n Self-Signed-CA -d /etc/dirsrv/ssca/ -a 2020-02-29T07:54:43Z DEBUG nss cmd: /usr/bin/c_rehash /etc/dirsrv/ssca/ 2020-02-29T07:54:44Z DEBUG nss cmd: /usr/bin/certutil -R --keyUsage digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment --nsCertType sslClient,sslServer --extKeyUsage clientAuth,serverAuth -s CN=vault-ca,givenName=3d2c6d03-a423-4fb7-bd2c-6e7b35be787f,O=testing,L=389ds,ST=Queensland,C=AU -8 vault-ca -g 4096 -d /etc/dirsrv/slapd-MYDOMAIN-LOCAL -z /etc/dirsrv/slapd-MYDOMAIN-LOCAL/noise.txt -f /etc/dirsrv/slapd-MYDOMAIN-LOCAL/pwdfile.txt -a -o /etc/dirsrv/slapd-MYDOMAIN-LOCAL/Server-Cert.csr 2020-02-29T07:54:50Z DEBUG nss cmd: /usr/bin/certutil -C -d /etc/dirsrv/ssca/ -f /etc/dirsrv/ssca//pwdfile.txt -v 24 -a -i /etc/dirsrv/slapd-MYDOMAIN-LOCAL/Server-Cert.csr -o /etc/dirsrv/slapd-MYDOMAIN-LOCAL/Server-Cert.crt -c Self-Signed-CA 2020-02-29T07:54:56Z DEBUG nss cmd: /usr/bin/c_rehash /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:54:56Z DEBUG nss cmd: /usr/bin/certutil -A -n Self-Signed-CA -t CT,, -a -i /etc/dirsrv/slapd-MYDOMAIN-LOCAL/ca.crt -d /etc/dirsrv/slapd-MYDOMAIN-LOCAL -f /etc/dirsrv/slapd-MYDOMAIN-LOCAL/pwdfile.txt 2020-02-29T07:55:01Z DEBUG nss cmd: /usr/bin/certutil -A -n Server-Cert -t ,, -a -i /etc/dirsrv/slapd-MYDOMAIN-LOCAL/Server-Cert.crt -d /etc/dirsrv/slapd-MYDOMAIN-LOCAL -f /etc/dirsrv/slapd-MYDOMAIN-LOCAL/pwdfile.txt 2020-02-29T07:55:06Z DEBUG nss cmd: /usr/bin/certutil -V -d /etc/dirsrv/slapd-MYDOMAIN-LOCAL -n Server-Cert -u YCV 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping port relabel 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /var/lib/dirsrv/slapd-MYDOMAIN-LOCAL/bak 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /var/lib/dirsrv/slapd-MYDOMAIN-LOCAL/db 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /var/lib/dirsrv/slapd-MYDOMAIN-LOCAL/ldif 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /var/lock/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /var/log/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /var/run/dirsrv 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /etc/dirsrv/slapd-MYDOMAIN-LOCAL/schema 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping relabel path /tmp 2020-02-29T07:55:11Z DEBUG selinux is disabled, skipping port relabel 2020-02-29T07:55:11Z DEBUG systemd status -> True 2020-02-29T07:55:11Z DEBUG systemd status -> True 2020-02-29T07:55:18Z DEBUG open(): Connecting to uri ldap://vault-ca:389/ 2020-02-29T07:55:18Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:18Z DEBUG Using external ca certificate /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:18Z DEBUG Using external ca certificate /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:18Z DEBUG Using certificate policy 1 2020-02-29T07:55:18Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 1 2020-02-29T07:55:18Z DEBUG open(): bound as cn=Directory Manager 2020-02-29T07:55:18Z DEBUG open(): Connecting to uri ldap://vault-ca:389/ 2020-02-29T07:55:18Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:18Z DEBUG Using external ca certificate /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:18Z DEBUG Using external ca certificate /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:55:18Z DEBUG Using certificate policy 1 2020-02-29T07:55:18Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 1 2020-02-29T07:55:18Z DEBUG open(): bound as cn=Directory Manager 2020-02-29T07:55:18Z DEBUG cn=config set REPLACE: ('nsslapd-secureport', '636') 2020-02-29T07:55:18Z DEBUG cn=config set REPLACE: ('nsslapd-security', 'on') 2020-02-29T07:55:18Z DEBUG Checking "None" under cn=ldbm database,cn=plugins,cn=config : {'cn': 'userRoot', 'nsslapd-suffix': 'dc=mydomain,dc=local'} 2020-02-29T07:55:18Z DEBUG Using first property cn: userRoot as rdn 2020-02-29T07:55:18Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=dc=mydomain,dc=local)(nsslapd-backend=dc=mydomain,dc=local))) 2020-02-29T07:55:18Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=userRoot)(nsslapd-backend=userRoot))) 2020-02-29T07:55:18Z DEBUG Validated dn cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-02-29T07:55:18Z DEBUG Creating cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-02-29T07:55:18Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-02-29T07:55:18Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance']} 2020-02-29T07:55:18Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-02-29T07:55:18Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=mydomain,dc=local']} 2020-02-29T07:55:18Z DEBUG Created entry cn=userRoot,cn=ldbm database,cn=plugins,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance'], 'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=mydomain,dc=local']} 2020-02-29T07:55:18Z DEBUG Checking "None" under cn=mapping tree,cn=config : {'cn': [b'dc=mydomain,dc=local'], 'nsslapd-state': 'backend', 'nsslapd-backend': [b'userRoot']} 2020-02-29T07:55:18Z DEBUG Using first property cn: dc\=mydomain\,dc\=local as rdn 2020-02-29T07:55:18Z DEBUG Validated dn cn=dc\=mydomain\,dc\=local,cn=mapping tree,cn=config 2020-02-29T07:55:18Z DEBUG Creating cn=dc\=mydomain\,dc\=local,cn=mapping tree,cn=config 2020-02-29T07:55:18Z DEBUG updating dn: cn=dc\=mydomain\,dc\=local,cn=mapping tree,cn=config 2020-02-29T07:55:18Z DEBUG updated dn: cn=dc\=mydomain\,dc\=local,cn=mapping tree,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree']} 2020-02-29T07:55:18Z DEBUG updating dn: cn=dc\=mydomain\,dc\=local,cn=mapping tree,cn=config 2020-02-29T07:55:18Z DEBUG updated dn: cn=dc\=mydomain\,dc\=local,cn=mapping tree,cn=config with {'cn': [b'dc=mydomain,dc=local', b'dc\\=mydomain\\,dc\\=local'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2020-02-29T07:55:18Z DEBUG Created entry cn=dc\=mydomain\,dc\=local,cn=mapping tree,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree'], 'cn': [b'dc=mydomain,dc=local', b'dc\\=mydomain\\,dc\\=local'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2020-02-29T07:55:18Z DEBUG cn=config set REPLACE: ('nsslapd-ldapifilepath', '/var/run/slapd-MYDOMAIN-LOCAL.socket') 2020-02-29T07:55:18Z DEBUG cn=config set REPLACE: ('nsslapd-ldapilisten', 'on') 2020-02-29T07:55:18Z DEBUG cn=config set REPLACE: ('nsslapd-ldapiautobind', 'on') 2020-02-29T07:55:18Z DEBUG cn=config set REPLACE: ('nsslapd-ldapimaprootdn', 'cn=Directory Manager') 2020-02-29T07:55:18Z DEBUG Adding sasl maps for suffix dc=mydomain,dc=local 2020-02-29T07:55:18Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'rfc 2829 u syntax', 'nsSaslMapRegexString': '^u:\\(.*\\)', 'nsSaslMapBaseDNTemplate': 'dc=mydomain,dc=local', 'nsSaslMapFilterTemplate': '(uid=\\1)'} 2020-02-29T07:55:18Z DEBUG Using first property cn: rfc 2829 u syntax as rdn 2020-02-29T07:55:18Z DEBUG Validated dn cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-02-29T07:55:18Z DEBUG Creating cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-02-29T07:55:18Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-02-29T07:55:18Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2020-02-29T07:55:18Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-02-29T07:55:18Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=mydomain,dc=local'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2020-02-29T07:55:18Z DEBUG Created entry cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=mydomain,dc=local'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2020-02-29T07:55:18Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'uid mapping', 'nsSaslMapRegexString': '^[^:@]+$', 'nsSaslMapBaseDNTemplate': 'dc=mydomain,dc=local', 'nsSaslMapFilterTemplate': '(uid=&)'} 2020-02-29T07:55:18Z DEBUG Using first property cn: uid mapping as rdn 2020-02-29T07:55:18Z DEBUG Validated dn cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-02-29T07:55:18Z DEBUG Creating cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-02-29T07:55:18Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-02-29T07:55:18Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2020-02-29T07:55:18Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-02-29T07:55:18Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=mydomain,dc=local'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2020-02-29T07:55:18Z DEBUG Created entry cn=uid mapping,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=mydomain,dc=local'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2020-02-29T07:55:18Z DEBUG cn=config set REPLACE: ('nsslapd-rootpw', '********') 2020-02-29T07:55:18Z DEBUG systemd status -> True 2020-02-29T07:55:18Z DEBUG systemd status -> True 2020-02-29T07:55:21Z DEBUG systemd status -> True 2020-02-29T07:55:21Z DEBUG systemd status -> True 2020-02-29T07:57:51Z DEBUG FINISH: Completed installation for MYDOMAIN-LOCAL 2020-02-29T07:57:51Z DEBUG Allocate local instance with ldapi://%2fvar%2frun%2fslapd-MYDOMAIN-LOCAL.socket 2020-02-29T07:57:51Z DEBUG open(): Connecting to uri ldapi://%2fvar%2frun%2fslapd-MYDOMAIN-LOCAL.socket 2020-02-29T07:57:51Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:57:51Z DEBUG Using external ca certificate /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:57:51Z DEBUG Using external ca certificate /etc/dirsrv/slapd-MYDOMAIN-LOCAL 2020-02-29T07:57:51Z DEBUG Using certificate policy 1 2020-02-29T07:57:51Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 1 2020-02-29T07:57:51Z DEBUG open(): bound as cn=Directory Manager 2020-02-29T07:57:51Z DEBUG Checking "None" under None : {'dc': 'mydomain', 'info': 'IPA V2.0'} 2020-02-29T07:57:51Z DEBUG Validated dn dc=mydomain,dc=local 2020-02-29T07:57:51Z DEBUG Creating dc=mydomain,dc=local 2020-02-29T07:57:51Z DEBUG updating dn: dc=mydomain,dc=local 2020-02-29T07:57:51Z DEBUG updated dn: dc=mydomain,dc=local with {'objectclass': [b'top', b'domain', b'pilotObject']} 2020-02-29T07:57:51Z DEBUG updating dn: dc=mydomain,dc=local 2020-02-29T07:57:51Z DEBUG updated dn: dc=mydomain,dc=local with {'dc': [b'mydomain'], 'info': [b'IPA V2.0']} 2020-02-29T07:57:51Z DEBUG Created entry dc=mydomain,dc=local : {'objectclass': [b'top', b'domain', b'pilotObject'], 'dc': [b'mydomain'], 'info': [b'IPA V2.0']} 2020-02-29T07:57:51Z DEBUG completed creating DS instance 2020-02-29T07:57:51Z DEBUG step duration: dirsrv __create_instance 218.69 sec 2020-02-29T07:57:51Z DEBUG [2/44]: configure autobind for root 2020-02-29T07:57:51Z DEBUG Starting external process 2020-02-29T07:57:51Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/root-autobind.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-MYDOMAIN-LOCAL.socket', '-x', '-D', 'cn=Directory Manager', '-y', '/tmp/tmpukplqh9c'] 2020-02-29T07:57:51Z DEBUG Process finished, return code=0 2020-02-29T07:57:51Z DEBUG stdout=add objectClass: extensibleObject top add cn: root-autobind add uidNumber: 0 add gidNumber: 0 adding new entry "cn=root-autobind,cn=config" modify complete replace nsslapd-ldapiautobind: on modifying entry "cn=config" modify complete replace nsslapd-ldapimaptoentries: on modifying entry "cn=config" modify complete 2020-02-29T07:57:51Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) 2020-02-29T07:57:51Z DEBUG step duration: dirsrv __root_autobind 0.03 sec 2020-02-29T07:57:51Z DEBUG [3/44]: stopping directory server 2020-02-29T07:57:51Z DEBUG Starting external process 2020-02-29T07:57:51Z DEBUG args=['/bin/systemctl', 'stop', 'dirsrv@MYDOMAIN-LOCAL.service'] 2020-02-29T07:57:54Z DEBUG Process finished, return code=0 2020-02-29T07:57:54Z DEBUG stdout= 2020-02-29T07:57:54Z DEBUG stderr= 2020-02-29T07:57:54Z DEBUG Stop of dirsrv@MYDOMAIN-LOCAL.service complete 2020-02-29T07:57:54Z DEBUG step duration: dirsrv __stop_instance 2.24 sec 2020-02-29T07:57:54Z DEBUG [4/44]: updating configuration in dse.ldif 2020-02-29T07:57:54Z DEBUG Starting external process 2020-02-29T07:57:54Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-02-29T07:57:54Z DEBUG Process finished, return code=1 2020-02-29T07:57:54Z DEBUG stdout= 2020-02-29T07:57:54Z DEBUG stderr= 2020-02-29T07:57:54Z DEBUG step duration: dirsrv __update_dse_ldif 0.03 sec 2020-02-29T07:57:54Z DEBUG [5/44]: starting directory server 2020-02-29T07:57:54Z DEBUG Starting external process 2020-02-29T07:57:54Z DEBUG args=['/bin/systemctl', 'start', 'dirsrv@MYDOMAIN-LOCAL.service'] 2020-02-29T07:58:08Z DEBUG Process finished, return code=0 2020-02-29T07:58:08Z DEBUG stdout= 2020-02-29T07:58:08Z DEBUG stderr= 2020-02-29T07:58:08Z DEBUG Starting external process 2020-02-29T07:58:08Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@MYDOMAIN-LOCAL.service'] 2020-02-29T07:58:08Z DEBUG Process finished, return code=0 2020-02-29T07:58:08Z DEBUG stdout=active 2020-02-29T07:58:08Z DEBUG stderr= 2020-02-29T07:58:08Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2020-02-29T07:58:08Z DEBUG waiting for port: 389 2020-02-29T07:58:08Z DEBUG SUCCESS: port: 389 2020-02-29T07:58:08Z DEBUG Start of dirsrv@MYDOMAIN-LOCAL.service complete 2020-02-29T07:58:08Z DEBUG Created connection context.ldap2_139637341046928 2020-02-29T07:58:08Z DEBUG step duration: dirsrv __start_instance 14.40 sec 2020-02-29T07:58:08Z DEBUG [6/44]: adding default schema 2020-02-29T07:58:08Z DEBUG step duration: dirsrv __add_default_schemas 0.01 sec 2020-02-29T07:58:08Z DEBUG [7/44]: enabling memberof plugin 2020-02-29T07:58:08Z DEBUG Starting external process 2020-02-29T07:58:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/memberof-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:08Z DEBUG Process finished, return code=0 2020-02-29T07:58:08Z DEBUG stdout=replace nsslapd-pluginenabled: on add memberofgroupattr: memberUser add memberofgroupattr: memberHost modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config" modify complete 2020-02-29T07:58:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:08Z DEBUG step duration: dirsrv __add_memberof_module 0.27 sec 2020-02-29T07:58:08Z DEBUG [8/44]: enabling winsync plugin 2020-02-29T07:58:08Z DEBUG Starting external process 2020-02-29T07:58:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-winsync-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:08Z DEBUG Process finished, return code=0 2020-02-29T07:58:08Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa-winsync add nsslapd-pluginpath: libipa_winsync add nsslapd-plugininitfunc: ipa_winsync_plugin_init add nsslapd-pluginDescription: Allows IPA to work with the DS windows sync feature add nsslapd-pluginid: ipa-winsync add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-plugin-depends-on-type: database add ipaWinSyncRealmFilter: (objectclass=krbRealmContainer) add ipaWinSyncRealmAttr: cn add ipaWinSyncNewEntryFilter: (cn=ipaConfig) add ipaWinSyncNewUserOCAttr: ipauserobjectclasses add ipaWinSyncUserFlatten: true add ipaWinsyncHomeDirAttr: ipaHomesRootDir add ipaWinsyncLoginShellAttr: ipaDefaultLoginShell add ipaWinSyncDefaultGroupAttr: ipaDefaultPrimaryGroup add ipaWinSyncDefaultGroupFilter: (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) add ipaWinSyncAcctDisable: both add ipaWinSyncForceSync: true add ipaWinSyncUserAttr: uidNumber -1 gidNumber -1 adding new entry "cn=ipa-winsync,cn=plugins,cn=config" modify complete 2020-02-29T07:58:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:08Z DEBUG step duration: dirsrv __add_winsync_module 0.02 sec 2020-02-29T07:58:08Z DEBUG [9/44]: configure password logging 2020-02-29T07:58:08Z DEBUG Starting external process 2020-02-29T07:58:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/pw-logging-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:08Z DEBUG Process finished, return code=0 2020-02-29T07:58:08Z DEBUG stdout=replace nsslapd-unhashed-pw-switch: nolog modifying entry "cn=config" modify complete 2020-02-29T07:58:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:08Z DEBUG step duration: dirsrv __password_logging 0.03 sec 2020-02-29T07:58:08Z DEBUG [10/44]: configuring replication version plugin 2020-02-29T07:58:08Z DEBUG Starting external process 2020-02-29T07:58:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/version-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Version Replication add nsslapd-pluginpath: libipa_repl_version add nsslapd-plugininitfunc: repl_version_plugin_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: off add nsslapd-pluginid: ipa_repl_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Replication version plugin add nsslapd-plugin-depends-on-type: database add nsslapd-plugin-depends-on-named: Multimaster Replication Plugin adding new entry "cn=IPA Version Replication,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __config_version_module 0.03 sec 2020-02-29T07:58:09Z DEBUG [11/44]: enabling IPA enrollment plugin 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpdkh2duz5', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_enrollment_extop add nsslapd-pluginpath: libipa_enrollment_extop add nsslapd-plugininitfunc: ipaenrollment_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_enrollment_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Enroll hosts into the IPA domain add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=mydomain,dc=local adding new entry "cn=ipa_enrollment_extop,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __add_enrollment_module 0.04 sec 2020-02-29T07:58:09Z DEBUG [12/44]: configuring uniqueness plugin 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpxlb_3anm', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: krbPrincipalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbPrincipalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=mydomain,dc=local add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=mydomain,dc=local add uniqueness-across-all-subtrees: on adding new entry "cn=krbPrincipalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: krbCanonicalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbCanonicalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=mydomain,dc=local add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=mydomain,dc=local add uniqueness-across-all-subtrees: on adding new entry "cn=krbCanonicalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: netgroup uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=ng,cn=alt,dc=mydomain,dc=local add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values adding new entry "cn=netgroup uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: ipaUniqueID uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: ipaUniqueID add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=mydomain,dc=local add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=mydomain,dc=local add uniqueness-across-all-subtrees: on adding new entry "cn=ipaUniqueID uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: sudorule name uniqueness add nsslapd-pluginDescription: Enforce unique attribute values add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=sudorules,cn=sudo,dc=mydomain,dc=local add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project adding new entry "cn=sudorule name uniqueness,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __set_unique_attrs 0.04 sec 2020-02-29T07:58:09Z DEBUG [13/44]: configuring uuid plugin 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/uuid-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA UUID add nsslapd-pluginpath: libipa_uuid add nsslapd-plugininitfunc: ipauuid_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipauuid_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA UUID plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA UUID,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpg1pqyehf', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectclass: top extensibleObject add cn: IPA Unique IDs add ipaUuidAttr: ipaUniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (|(objectclass=ipaObject)(objectclass=ipaAssociation)) add ipaUuidScope: dc=mydomain,dc=local add ipaUuidEnforce: TRUE adding new entry "cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: IPK11 Unique IDs add ipaUuidAttr: ipk11UniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (objectclass=ipk11Object) add ipaUuidScope: dc=mydomain,dc=local add ipaUuidEnforce: FALSE adding new entry "cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __config_uuid_module 0.06 sec 2020-02-29T07:58:09Z DEBUG [14/44]: configuring modrdn plugin 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/modrdn-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA MODRDN add nsslapd-pluginpath: libipa_modrdn add nsslapd-plugininitfunc: ipamodrdn_init add nsslapd-plugintype: betxnpostoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipamodrdn_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA MODRDN plugin add nsslapd-plugin-depends-on-type: database add nsslapd-pluginPrecedence: 60 adding new entry "cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpx416ch_p', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectclass: top extensibleObject add cn: Kerberos Principal Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbPrincipalName add ipaModRDNsuffix: @MYDOMAIN.LOCAL add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=mydomain,dc=local adding new entry "cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: Kerberos Canonical Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbCanonicalName add ipaModRDNsuffix: @MYDOMAIN.LOCAL add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=mydomain,dc=local adding new entry "cn=Kerberos Canonical Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __config_modrdn_module 0.06 sec 2020-02-29T07:58:09Z DEBUG [15/44]: configuring DNS plugin 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-dns-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectclass: top nsslapdPlugin extensibleObject add cn: IPA DNS add nsslapd-plugindescription: IPA DNS support plugin add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_dns add nsslapd-plugininitfunc: ipadns_init add nsslapd-pluginpath: libipa_dns.so add nsslapd-plugintype: preoperation add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-pluginversion: 1.0 add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA DNS,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __config_dns_module 0.02 sec 2020-02-29T07:58:09Z DEBUG [16/44]: enabling entryUSN plugin 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/entryusn.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=replace nsslapd-entryusn-global: on modifying entry "cn=config" modify complete replace nsslapd-entryusn-import-initval: next modifying entry "cn=config" modify complete replace nsslapd-pluginenabled: on modifying entry "cn=USN,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __enable_entryusn 0.05 sec 2020-02-29T07:58:09Z DEBUG [17/44]: configuring lockout plugin 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/lockout-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Lockout add nsslapd-pluginpath: libipa_lockout add nsslapd-plugininitfunc: ipalockout_init add nsslapd-plugintype: object add nsslapd-pluginenabled: on add nsslapd-pluginid: ipalockout_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Lockout plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA Lockout,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __config_lockout_module 0.02 sec 2020-02-29T07:58:09Z DEBUG [18/44]: configuring topology plugin 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpxyuubtni', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: IPA Topology Configuration add nsslapd-pluginPath: libtopology add nsslapd-pluginInitfunc: ipa_topo_init add nsslapd-pluginType: object add nsslapd-pluginEnabled: on add nsslapd-topo-plugin-shared-config-base: cn=ipa,cn=etc,dc=mydomain,dc=local add nsslapd-topo-plugin-shared-replica-root: dc=mydomain,dc=local o=ipaca add nsslapd-topo-plugin-shared-binddngroup: cn=replication managers,cn=sysaccounts,cn=etc,dc=mydomain,dc=local add nsslapd-topo-plugin-startup-delay: 20 add nsslapd-pluginId: none add nsslapd-plugin-depends-on-named: ldbm database Multimaster Replication Plugin add nsslapd-pluginVersion: 1.0 add nsslapd-pluginVendor: none add nsslapd-pluginDescription: none adding new entry "cn=IPA Topology Configuration,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __config_topology_module 0.03 sec 2020-02-29T07:58:09Z DEBUG [19/44]: creating indices 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/indices.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add objectClass: top nsIndex add cn: krbPrincipalName add nsSystemIndex: false add nsIndexType: eq sub add nsMatchingRule: caseIgnoreIA5Match caseExactIA5Match adding new entry "cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: ou add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: carLicense add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: title add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: manager add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: secretary add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: displayname add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add nsIndexType: sub modifying entry "cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: uidnumber add nsSystemIndex: false add nsIndexType: eq add nsMatchingRule: integerOrderingMatch adding new entry "cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: gidnumber add nsSystemIndex: false add nsIndexType: eq add nsMatchingRule: integerOrderingMatch adding new entry "cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete replace nsIndexType: eq pres modifying entry "cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete replace nsIndexType: eq pres modifying entry "cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add ObjectClass: top nsIndex add cn: fqdn add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add ObjectClass: top nsIndex add cn: macAddress add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberHost add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberUser add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: sourcehost add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberservice add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: managedby add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberallowcmd add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberdenycmd add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipasudorunas add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipasudorunasgroup add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: automountkey add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: automountMapName add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaConfigString add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaEnabledFlag add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaKrbAuthzData add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipakrbprincipalalias add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipauniqueid add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaMemberCa add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaMemberCertProfile add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: userCertificate add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipalocation add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: krbCanonicalName add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: serverhostname add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: description add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: l add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsOsVersion add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsHardwarePlatform add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsHostLocation add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipServicePort add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: accessRuleType add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: hostCategory add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: idnsName add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaCertmapData add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: altSecurityIdentities add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberManager add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __create_indices 0.24 sec 2020-02-29T07:58:09Z DEBUG [20/44]: enabling referential integrity plugin 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/referint-conf.ldif', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=replace nsslapd-pluginenabled: on modifying entry "cn=referential integrity postoperation,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __add_referint_module 0.02 sec 2020-02-29T07:58:09Z DEBUG [21/44]: configuring certmap.conf 2020-02-29T07:58:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T07:58:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T07:58:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __certmap_conf 0.00 sec 2020-02-29T07:58:09Z DEBUG [22/44]: configure new location for managed entries 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpal9cqy59', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=Definitions,cn=Managed Entries,cn=etc,dc=mydomain,dc=local modifying entry "cn=Managed Entries,cn=plugins,cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __repoint_managed_entries 0.03 sec 2020-02-29T07:58:09Z DEBUG [23/44]: configure dirsrv ccache and keytab 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=1 2020-02-29T07:58:09Z DEBUG stdout= 2020-02-29T07:58:09Z DEBUG stderr= 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout= 2020-02-29T07:58:09Z DEBUG stderr= 2020-02-29T07:58:09Z DEBUG step duration: dirsrv configure_systemd_ipa_env 0.21 sec 2020-02-29T07:58:09Z DEBUG [24/44]: enabling SASL mapping fallback 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmptwztz9is', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:09Z DEBUG Process finished, return code=0 2020-02-29T07:58:09Z DEBUG stdout=replace nsslapd-sasl-mapping-fallback: on modifying entry "cn=config" modify complete 2020-02-29T07:58:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:09Z DEBUG step duration: dirsrv __enable_sasl_mapping_fallback 0.03 sec 2020-02-29T07:58:09Z DEBUG [25/44]: restarting directory server 2020-02-29T07:58:09Z DEBUG Destroyed connection context.ldap2_139637341046928 2020-02-29T07:58:09Z DEBUG Starting external process 2020-02-29T07:58:09Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2020-02-29T07:58:10Z DEBUG Process finished, return code=0 2020-02-29T07:58:10Z DEBUG stdout= 2020-02-29T07:58:10Z DEBUG stderr= 2020-02-29T07:58:10Z DEBUG Starting external process 2020-02-29T07:58:10Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@MYDOMAIN-LOCAL.service'] 2020-02-29T07:58:25Z DEBUG Process finished, return code=0 2020-02-29T07:58:25Z DEBUG stdout= 2020-02-29T07:58:25Z DEBUG stderr= 2020-02-29T07:58:25Z DEBUG Starting external process 2020-02-29T07:58:25Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@MYDOMAIN-LOCAL.service'] 2020-02-29T07:58:25Z DEBUG Process finished, return code=0 2020-02-29T07:58:25Z DEBUG stdout=active 2020-02-29T07:58:25Z DEBUG stderr= 2020-02-29T07:58:25Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2020-02-29T07:58:25Z DEBUG waiting for port: 389 2020-02-29T07:58:25Z DEBUG SUCCESS: port: 389 2020-02-29T07:58:25Z DEBUG Restart of dirsrv@MYDOMAIN-LOCAL.service complete 2020-02-29T07:58:25Z DEBUG Starting external process 2020-02-29T07:58:25Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@MYDOMAIN-LOCAL.service'] 2020-02-29T07:58:25Z DEBUG Process finished, return code=0 2020-02-29T07:58:25Z DEBUG stdout=active 2020-02-29T07:58:25Z DEBUG stderr= 2020-02-29T07:58:25Z DEBUG Created connection context.ldap2_139637341046928 2020-02-29T07:58:25Z DEBUG step duration: dirsrv __restart_instance 15.23 sec 2020-02-29T07:58:25Z DEBUG [26/44]: adding sasl mappings to the directory 2020-02-29T07:58:25Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket from SchemaCache 2020-02-29T07:58:25Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket conn= 2020-02-29T07:58:25Z DEBUG step duration: dirsrv __configure_sasl_mappings 0.28 sec 2020-02-29T07:58:25Z DEBUG [27/44]: adding default layout 2020-02-29T07:58:25Z DEBUG Starting external process 2020-02-29T07:58:25Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp4_6iv6ch', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:26Z DEBUG Process finished, return code=0 2020-02-29T07:58:26Z DEBUG stdout=add objectClass: top nsContainer add cn: accounts adding new entry "cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: users adding new entry "cn=users,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: groups adding new entry "cn=groups,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: services adding new entry "cn=services,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: computers adding new entry "cn=computers,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: hostgroups adding new entry "cn=hostgroups,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: ipservices adding new entry "cn=ipservices,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: nsContainer add cn: alt adding new entry "cn=alt,dc=mydomain,dc=local" modify complete add objectClass: nsContainer add cn: ng adding new entry "cn=ng,cn=alt,dc=mydomain,dc=local" modify complete add objectClass: nsContainer add cn: automount adding new entry "cn=automount,dc=mydomain,dc=local" modify complete add objectClass: nsContainer add cn: default adding new entry "cn=default,cn=automount,dc=mydomain,dc=local" modify complete add objectClass: automountMap add automountMapName: auto.master adding new entry "automountmapname=auto.master,cn=default,cn=automount,dc=mydomain,dc=local" modify complete add objectClass: automountMap add automountMapName: auto.direct adding new entry "automountmapname=auto.direct,cn=default,cn=automount,dc=mydomain,dc=local" modify complete add objectClass: automount add automountKey: /- add automountInformation: auto.direct add description: /- auto.direct adding new entry "description=/- auto.direct,automountmapname=auto.master,cn=default,cn=automount,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: hbac adding new entry "cn=hbac,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: hbacservices adding new entry "cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: hbacservicegroups adding new entry "cn=hbacservicegroups,cn=hbac,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: sudo adding new entry "cn=sudo,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: sudocmds adding new entry "cn=sudocmds,cn=sudo,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: sudocmdgroups adding new entry "cn=sudocmdgroups,cn=sudo,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: sudorules adding new entry "cn=sudorules,cn=sudo,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: etc adding new entry "cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: locations adding new entry "cn=locations,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: sysaccounts adding new entry "cn=sysaccounts,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: ipa adding new entry "cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: masters adding new entry "cn=masters,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: replicas adding new entry "cn=replicas,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: dna adding new entry "cn=dna,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: posix-ids adding new entry "cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: ca_renewal adding new entry "cn=ca_renewal,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: certificates adding new entry "cn=certificates,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: custodia adding new entry "cn=custodia,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: dogtag adding new entry "cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: s4u2proxy adding new entry "cn=s4u2proxy,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: ipaKrb5DelegationACL groupOfPrincipals top add cn: ipa-http-delegation add memberPrincipal: HTTP/vault-ca.mydomain.local@MYDOMAIN.LOCAL add ipaAllowedTarget: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=mydomain,dc=local cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=mydomain,dc=local adding new entry "cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: groupOfPrincipals top add cn: ipa-ldap-delegation-targets add memberPrincipal: ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL adding new entry "cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: groupOfPrincipals top add cn: ipa-cifs-delegation-targets adding new entry "cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: top person posixaccount krbprincipalaux krbticketpolicyaux inetuser ipaobject ipasshuser add uid: admin add krbPrincipalName: admin@MYDOMAIN.LOCAL add cn: Administrator add sn: Administrator add uidNumber: 865000000 add gidNumber: 865000000 add homeDirectory: /home/admin add loginShell: /bin/bash add gecos: Administrator add nsAccountLock: FALSE add ipaUniqueID: autogenerate adding new entry "uid=admin,cn=users,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames posixgroup ipausergroup ipaobject add cn: admins add description: Account administrators group add gidNumber: 865000000 add member: uid=admin,cn=users,cn=accounts,dc=mydomain,dc=local add nsAccountLock: FALSE add ipaUniqueID: autogenerate adding new entry "cn=admins,cn=groups,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup ipausergroup ipaobject add description: Default group for all users add cn: ipausers add ipaUniqueID: autogenerate adding new entry "cn=ipausers,cn=groups,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames posixgroup ipausergroup ipaobject add gidNumber: 865000002 add description: Limited admins who can edit other users add cn: editors add ipaUniqueID: autogenerate adding new entry "cn=editors,cn=groups,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top groupOfNames nestedGroup ipaobject ipahostgroup add description: IPA server hosts add cn: ipaservers add ipaUniqueID: autogenerate adding new entry "cn=ipaservers,cn=hostgroups,cn=accounts,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: sshd add description: sshd add ipauniqueid: autogenerate adding new entry "cn=sshd,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: ftp add description: ftp add ipauniqueid: autogenerate adding new entry "cn=ftp,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: su add description: su add ipauniqueid: autogenerate adding new entry "cn=su,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: login add description: login add ipauniqueid: autogenerate adding new entry "cn=login,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: su-l add description: su with login shell add ipauniqueid: autogenerate adding new entry "cn=su-l,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: sudo add description: sudo add ipauniqueid: autogenerate adding new entry "cn=sudo,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: sudo-i add description: sudo-i add ipauniqueid: autogenerate adding new entry "cn=sudo-i,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: systemd-user add description: pam_systemd and systemd user@.service add ipauniqueid: autogenerate adding new entry "cn=systemd-user,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: gdm add description: gdm add ipauniqueid: autogenerate adding new entry "cn=gdm,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: gdm-password add description: gdm-password add ipauniqueid: autogenerate adding new entry "cn=gdm-password,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipahbacservice ipaobject add cn: kdm add description: kdm add ipauniqueid: autogenerate adding new entry "cn=kdm,cn=hbacservices,cn=hbac,dc=mydomain,dc=local" modify complete add objectClass: ipaobject ipahbacservicegroup nestedGroup groupOfNames top add cn: Sudo add ipauniqueid: autogenerate add description: Default group of Sudo related services add member: cn=sudo,cn=hbacservices,cn=hbac,dc=mydomain,dc=local cn=sudo-i,cn=hbacservices,cn=hbac,dc=mydomain,dc=local adding new entry "cn=Sudo,cn=hbacservicegroups,cn=hbac,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top ipaGuiConfig ipaConfigObject add ipaUserSearchFields: uid,givenname,sn,telephonenumber,ou,title add ipaGroupSearchFields: cn,description add ipaSearchTimeLimit: 2 add ipaSearchRecordsLimit: 100 add ipaHomesRootDir: /home add ipaDefaultLoginShell: /bin/sh add ipaDefaultPrimaryGroup: ipausers add ipaMaxUsernameLength: 32 add ipaMaxHostnameLength: 64 add ipaPwdExpAdvNotify: 4 add ipaGroupObjectClasses: top groupofnames nestedgroup ipausergroup ipaobject add ipaUserObjectClasses: top person organizationalperson inetorgperson inetuser posixaccount krbprincipalaux krbticketpolicyaux ipaobject ipasshuser add ipaDefaultEmailDomain: mydomain.local add ipaMigrationEnabled: FALSE add ipaConfigString: AllowNThash KDC:Disable Last Success add ipaSELinuxUserMapOrder: guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 add ipaSELinuxUserMapDefault: unconfined_u:s0-s0:c0.c1023 adding new entry "cn=ipaConfig,cn=etc,dc=mydomain,dc=local" modify complete add objectclass: top nsContainer add cn: cosTemplates adding new entry "cn=cosTemplates,cn=accounts,dc=mydomain,dc=local" modify complete add description: Password Policy based on group membership add objectClass: top ldapsubentry cosSuperDefinition cosClassicDefinition add cosTemplateDn: cn=cosTemplates,cn=accounts,dc=mydomain,dc=local add cosAttribute: krbPwdPolicyReference override add cosSpecifier: memberOf adding new entry "cn=Password Policy,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: selinux adding new entry "cn=selinux,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: usermap adding new entry "cn=usermap,cn=selinux,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: ranges adding new entry "cn=ranges,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: top ipaIDrange ipaDomainIDRange add cn: MYDOMAIN.LOCAL_id_range add ipaBaseID: 865000000 add ipaIDRangeSize: 200000 add ipaRangeType: ipa-local adding new entry "cn=MYDOMAIN.LOCAL_id_range,cn=ranges,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: ca adding new entry "cn=ca,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: certprofiles adding new entry "cn=certprofiles,cn=ca,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: caacls adding new entry "cn=caacls,cn=ca,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: cas adding new entry "cn=cas,cn=ca,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:26Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:26Z DEBUG step duration: dirsrv __add_default_layout 0.97 sec 2020-02-29T07:58:26Z DEBUG [28/44]: adding delegation layout 2020-02-29T07:58:26Z DEBUG Starting external process 2020-02-29T07:58:26Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpzvb_a4pn', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:26Z DEBUG Process finished, return code=0 2020-02-29T07:58:26Z DEBUG stdout=add objectClass: top nsContainer add cn: roles adding new entry "cn=roles,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: pbac adding new entry "cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: privileges adding new entry "cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: permissions adding new entry "cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: helpdesk add description: Helpdesk adding new entry "cn=helpdesk,cn=roles,cn=accounts,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: User Administrators add description: User Administrators adding new entry "cn=User Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Group Administrators add description: Group Administrators adding new entry "cn=Group Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Administrators add description: Host Administrators adding new entry "cn=Host Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Group Administrators add description: Host Group Administrators adding new entry "cn=Host Group Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Delegation Administrator add description: Role administration adding new entry "cn=Delegation Administrator,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: DNS Administrators add description: DNS Administrators adding new entry "cn=DNS Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: DNS Servers add description: DNS Servers adding new entry "cn=DNS Servers,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Service Administrators add description: Service Administrators adding new entry "cn=Service Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Automount Administrators add description: Automount Administrators adding new entry "cn=Automount Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Netgroups Administrators add description: Netgroups Administrators adding new entry "cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Certificate Administrators add description: Certificate Administrators adding new entry "cn=Certificate Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Replication Administrators add description: Replication Administrators add member: cn=admins,cn=groups,cn=accounts,dc=mydomain,dc=local adding new entry "cn=Replication Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Enrollment add description: Host Enrollment adding new entry "cn=Host Enrollment,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Stage User Administrators add description: Stage User Administrators adding new entry "cn=Stage User Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames nestedgroup add cn: Stage User Provisioning add description: Stage User Provisioning adding new entry "cn=Stage User Provisioning,cn=privileges,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Add Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Modify Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Read Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Remove Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Modify DNA Range add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Modify DNA Range,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer add cn: virtual operations adding new entry "cn=virtual operations,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Retrieve Certificates from the CA add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=mydomain,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Request Certificate add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Request Certificate,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=mydomain,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Request Certificates from a different host add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=mydomain,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Get Certificates status from the CA add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=mydomain,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Revoke Certificate add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Revoke Certificate,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=mydomain,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "dc=mydomain,dc=local" modify complete add objectClass: top groupofnames ipapermission add cn: Certificate Remove Hold add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=mydomain,dc=local adding new entry "cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=mydomain,dc=local" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=mydomain,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "dc=mydomain,dc=local" modify complete 2020-02-29T07:58:26Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:26Z DEBUG step duration: dirsrv __add_delegation_layout 0.53 sec 2020-02-29T07:58:26Z DEBUG [29/44]: creating container for managed entries 2020-02-29T07:58:26Z DEBUG Starting external process 2020-02-29T07:58:26Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp84u2yi7i', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:26Z DEBUG Process finished, return code=0 2020-02-29T07:58:26Z DEBUG stdout=add objectClass: nsContainer top add cn: Managed Entries adding new entry "cn=Managed Entries,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: Templates adding new entry "cn=Templates,cn=Managed Entries,cn=etc,dc=mydomain,dc=local" modify complete add objectClass: nsContainer top add cn: Definitions adding new entry "cn=Definitions,cn=Managed Entries,cn=etc,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:26Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:26Z DEBUG step duration: dirsrv __managed_entries 0.05 sec 2020-02-29T07:58:26Z DEBUG [30/44]: configuring user private groups 2020-02-29T07:58:26Z DEBUG Starting external process 2020-02-29T07:58:26Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpova3wzb_', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:26Z DEBUG Process finished, return code=0 2020-02-29T07:58:26Z DEBUG stdout=add objectclass: mepTemplateEntry add cn: UPG Template add mepRDNAttr: cn add mepStaticAttr: objectclass: posixgroup objectclass: ipaobject ipaUniqueId: autogenerate add mepMappedAttr: cn: $uid gidNumber: $uidNumber description: User private group for $uid adding new entry "cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=mydomain,dc=local" modify complete add objectclass: extensibleObject add cn: UPG Definition add originScope: cn=users,cn=accounts,dc=mydomain,dc=local add originFilter: (&(objectclass=posixAccount)(!(description=__no_upg__))) add managedBase: cn=groups,cn=accounts,dc=mydomain,dc=local add managedTemplate: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=mydomain,dc=local adding new entry "cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:26Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:26Z DEBUG step duration: dirsrv __user_private_groups 0.04 sec 2020-02-29T07:58:26Z DEBUG [31/44]: configuring netgroups from hostgroups 2020-02-29T07:58:26Z DEBUG Starting external process 2020-02-29T07:58:26Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp_tml7jm_', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:26Z DEBUG Process finished, return code=0 2020-02-29T07:58:26Z DEBUG stdout=add objectclass: mepTemplateEntry add cn: NGP HGP Template add mepRDNAttr: cn add mepStaticAttr: ipaUniqueId: autogenerate objectclass: ipanisnetgroup objectclass: ipaobject nisDomainName: mydomain.local add mepMappedAttr: cn: $cn memberHost: $dn description: ipaNetgroup $cn adding new entry "cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=mydomain,dc=local" modify complete add objectclass: extensibleObject add cn: NGP Definition add originScope: cn=hostgroups,cn=accounts,dc=mydomain,dc=local add originFilter: objectclass=ipahostgroup add managedBase: cn=ng,cn=alt,dc=mydomain,dc=local add managedTemplate: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=mydomain,dc=local adding new entry "cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:26Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:26Z DEBUG step duration: dirsrv __host_nis_groups 0.04 sec 2020-02-29T07:58:26Z DEBUG [32/44]: creating default Sudo bind user 2020-02-29T07:58:26Z DEBUG Starting external process 2020-02-29T07:58:26Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp4pw02hbv', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:27Z DEBUG Process finished, return code=0 2020-02-29T07:58:27Z DEBUG stdout=add objectclass: account simplesecurityobject add uid: sudo add userPassword: XXXXXXXX add passwordExpirationTime: 20380119031407Z add nsIdleTimeout: 0 adding new entry "uid=sudo,cn=sysaccounts,cn=etc,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:27Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:27Z DEBUG step duration: dirsrv __add_sudo_binduser 0.09 sec 2020-02-29T07:58:27Z DEBUG [33/44]: creating default Auto Member layout 2020-02-29T07:58:27Z DEBUG Starting external process 2020-02-29T07:58:27Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp87bjaxli', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:27Z DEBUG Process finished, return code=0 2020-02-29T07:58:27Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=automember,cn=etc,dc=mydomain,dc=local modifying entry "cn=Auto Membership Plugin,cn=plugins,cn=config" modify complete add objectClass: top nsContainer add cn: automember adding new entry "cn=automember,cn=etc,dc=mydomain,dc=local" modify complete add objectclass: autoMemberDefinition add cn: Hostgroup add autoMemberScope: cn=computers,cn=accounts,dc=mydomain,dc=local add autoMemberFilter: objectclass=ipaHost add autoMemberGroupingAttr: member:dn adding new entry "cn=Hostgroup,cn=automember,cn=etc,dc=mydomain,dc=local" modify complete add objectclass: autoMemberDefinition add cn: Group add autoMemberScope: cn=users,cn=accounts,dc=mydomain,dc=local add autoMemberFilter: objectclass=posixAccount add autoMemberGroupingAttr: member:dn adding new entry "cn=Group,cn=automember,cn=etc,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:27Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:27Z DEBUG step duration: dirsrv __add_automember_config 0.06 sec 2020-02-29T07:58:27Z DEBUG [34/44]: adding range check plugin 2020-02-29T07:58:27Z DEBUG Starting external process 2020-02-29T07:58:27Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpesjra14s', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:27Z DEBUG Process finished, return code=0 2020-02-29T07:58:27Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Range-Check add nsslapd-pluginpath: libipa_range_check add nsslapd-plugininitfunc: ipa_range_check_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_range_check_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Range-Check plugin add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=mydomain,dc=local adding new entry "cn=IPA Range-Check,cn=plugins,cn=config" modify complete 2020-02-29T07:58:27Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:27Z DEBUG step duration: dirsrv __add_range_check_plugin 0.02 sec 2020-02-29T07:58:27Z DEBUG [35/44]: creating default HBAC rule allow_all 2020-02-29T07:58:27Z DEBUG Starting external process 2020-02-29T07:58:27Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpltw84g4z', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:27Z DEBUG Process finished, return code=0 2020-02-29T07:58:27Z DEBUG stdout=add objectclass: ipaassociation ipahbacrule add cn: allow_all add accessruletype: allow add usercategory: all add hostcategory: all add servicecategory: all add ipaenabledflag: TRUE add description: Allow all users to access any host from any host add ipauniqueid: autogenerate adding new entry "ipauniqueid=autogenerate,cn=hbac,dc=mydomain,dc=local" modify complete add objectclass: ipaassociation ipahbacrule add cn: allow_systemd-user add accessruletype: allow add usercategory: all add hostcategory: all add memberService: cn=systemd-user,cn=hbacservices,cn=hbac,dc=mydomain,dc=local add ipaenabledflag: TRUE add description: Allow pam_systemd to run user@.service to create a system user session add ipauniqueid: autogenerate adding new entry "ipauniqueid=autogenerate,cn=hbac,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:27Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:27Z DEBUG step duration: dirsrv add_hbac 0.14 sec 2020-02-29T07:58:27Z DEBUG [36/44]: adding entries for topology management 2020-02-29T07:58:27Z DEBUG Starting external process 2020-02-29T07:58:27Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp3aakkxqy', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:27Z DEBUG Process finished, return code=0 2020-02-29T07:58:27Z DEBUG stdout=add objectclass: top nsContainer add cn: topology adding new entry "cn=topology,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add objectclass: top iparepltopoconf add ipaReplTopoConfRoot: dc=mydomain,dc=local add nsDS5ReplicatedAttributeList: (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount add nsDS5ReplicatedAttributeListTotal: (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount add nsds5ReplicaStripAttrs: modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp add cn: domain adding new entry "cn=domain,cn=topology,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:27Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:27Z DEBUG step duration: dirsrv __add_topology_entries 0.04 sec 2020-02-29T07:58:27Z DEBUG [37/44]: initializing group membership 2020-02-29T07:58:27Z DEBUG Starting external process 2020-02-29T07:58:27Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpf2r42dvp', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:27Z DEBUG Process finished, return code=0 2020-02-29T07:58:27Z DEBUG stdout=add objectClass: top extensibleObject add cn: IPA install add basedn: dc=mydomain,dc=local add filter: (objectclass=*) add ttl: 10 adding new entry "cn=IPA install 1582962853, cn=memberof task, cn=tasks, cn=config" modify complete 2020-02-29T07:58:27Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:27Z DEBUG Waiting for memberof task to complete. 2020-02-29T07:58:28Z DEBUG step duration: dirsrv init_memberof 1.03 sec 2020-02-29T07:58:28Z DEBUG [38/44]: adding master entry 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpm1o5yxu2', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout=add objectclass: top nsContainer ipaReplTopoManagedServer ipaConfigObject ipaSupportedDomainLevelConfig add cn: vault-ca.mydomain.local add ipaReplTopoManagedSuffix: dc=mydomain,dc=local add ipaMinDomainLevel: 1 add ipaMaxDomainLevel: 1 adding new entry "cn=vault-ca.mydomain.local,cn=masters,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:28Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:28Z DEBUG step duration: dirsrv __add_master_entry 0.03 sec 2020-02-29T07:58:28Z DEBUG [39/44]: initializing domain level 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpxse59c2j', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout=add objectClass: top nsContainer ipaDomainLevelConfig add ipaDomainLevel: 1 adding new entry "cn=Domain Level,cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:28Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:28Z DEBUG step duration: dirsrv __set_domain_level 0.04 sec 2020-02-29T07:58:28Z DEBUG [40/44]: configuring Posix uid/gid generation 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp0ry60t_c', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout=add objectclass: top extensibleObject add cn: Posix IDs add dnaType: uidNumber gidNumber add dnaNextValue: 865000000 add dnaMaxValue: 865199999 add dnaMagicRegen: -1 add dnaFilter: (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) add dnaScope: dc=mydomain,dc=local add dnaThreshold: 500 add dnaSharedCfgDN: cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=mydomain,dc=local add dnaExcludeScope: cn=provisioning,dc=mydomain,dc=local adding new entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete replace nsslapd-pluginEnabled: on modifying entry "cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete 2020-02-29T07:58:28Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:28Z DEBUG step duration: dirsrv __config_uidgid_gen 0.05 sec 2020-02-29T07:58:28Z DEBUG [41/44]: adding replication acis 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpn24eqev8', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout=add aci: (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete add aci: (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add aci: (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=mydomain,dc=local";) modifying entry "cn=tasks,cn=config" modify complete 2020-02-29T07:58:28Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:28Z DEBUG step duration: dirsrv __add_replication_acis 0.07 sec 2020-02-29T07:58:28Z DEBUG [42/44]: activating sidgen plugin 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpn1e542an', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA SIDGEN add nsslapd-pluginpath: libipa_sidgen add nsslapd-plugininitfunc: ipa_sidgen_init add nsslapd-plugintype: postoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_sidgen_postop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA SIDGEN post operation add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=mydomain,dc=local adding new entry "cn=IPA SIDGEN,cn=plugins,cn=config" modify complete 2020-02-29T07:58:28Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:28Z DEBUG step duration: dirsrv _add_sidgen_plugin 0.02 sec 2020-02-29T07:58:28Z DEBUG [43/44]: activating extdom plugin 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp99ceyas4', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_extdom_extop add nsslapd-pluginpath: libipa_extdom_extop add nsslapd-plugininitfunc: ipa_extdom_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_extdom_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support resolving IDs in trusted domains to names and back add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=mydomain,dc=local adding new entry "cn=ipa_extdom_extop,cn=plugins,cn=config" modify complete 2020-02-29T07:58:28Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:28Z DEBUG step duration: dirsrv _add_extdom_plugin 0.12 sec 2020-02-29T07:58:28Z DEBUG [44/44]: configuring directory to start on boot 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/bin/systemctl', 'is-enabled', 'dirsrv@MYDOMAIN-LOCAL.service'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout=enabled 2020-02-29T07:58:28Z DEBUG stderr= 2020-02-29T07:58:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:28Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/bin/systemctl', 'disable', 'dirsrv@MYDOMAIN-LOCAL.service'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout= 2020-02-29T07:58:28Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/dirsrv@MYDOMAIN-LOCAL.service. Removed /etc/systemd/system/dirsrv.target.wants/dirsrv@MYDOMAIN-LOCAL.service. 2020-02-29T07:58:28Z DEBUG step duration: dirsrv __enable 0.21 sec 2020-02-29T07:58:28Z DEBUG Done configuring directory server (dirsrv). 2020-02-29T07:58:28Z DEBUG service duration: dirsrv 255.65 sec 2020-02-29T07:58:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout=910586801 2020-02-29T07:58:28Z DEBUG stderr= 2020-02-29T07:58:28Z DEBUG Enabling persistent keyring CCACHE 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=3 2020-02-29T07:58:28Z DEBUG stdout=inactive 2020-02-29T07:58:28Z DEBUG stderr= 2020-02-29T07:58:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:28Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/bin/systemctl', 'stop', 'krb5kdc.service'] 2020-02-29T07:58:28Z DEBUG Process finished, return code=0 2020-02-29T07:58:28Z DEBUG stdout= 2020-02-29T07:58:28Z DEBUG stderr= 2020-02-29T07:58:28Z DEBUG Stop of krb5kdc.service complete 2020-02-29T07:58:28Z DEBUG Configuring Kerberos KDC (krb5kdc) 2020-02-29T07:58:28Z DEBUG [1/10]: adding kerberos container to the directory 2020-02-29T07:58:28Z DEBUG Starting external process 2020-02-29T07:58:28Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpg77rdmf8', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:29Z DEBUG Process finished, return code=0 2020-02-29T07:58:29Z DEBUG stdout=add objectClass: krbContainer top add cn: kerberos adding new entry "cn=kerberos,dc=mydomain,dc=local" modify complete add cn: MYDOMAIN.LOCAL add objectClass: top krbrealmcontainer krbticketpolicyaux add krbSubTrees: dc=mydomain,dc=local add krbSearchScope: 2 add krbSupportedEncSaltTypes: aes256-cts:normal aes256-cts:special aes128-cts:normal aes128-cts:special aes128-sha2:normal aes128-sha2:special aes256-sha2:normal aes256-sha2:special camellia128-cts-cmac:normal camellia128-cts-cmac:special camellia256-cts-cmac:normal camellia256-cts-cmac:special add krbMaxTicketLife: 86400 add krbMaxRenewableAge: 604800 add krbDefaultEncSaltTypes: aes256-cts:special aes128-cts:special adding new entry "cn=MYDOMAIN.LOCAL,cn=kerberos,dc=mydomain,dc=local" modify complete add objectClass: top nsContainer krbPwdPolicy add krbMinPwdLife: 3600 add krbPwdMinDiffChars: 0 add krbPwdMinLength: 8 add krbPwdHistoryLength: 0 add krbMaxPwdLife: 7776000 add krbPwdMaxFailure: 6 add krbPwdFailureCountInterval: 60 add krbPwdLockoutDuration: 600 adding new entry "cn=global_policy,cn=MYDOMAIN.LOCAL,cn=kerberos,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:29Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:29Z DEBUG step duration: krb5kdc __add_krb_container 0.05 sec 2020-02-29T07:58:29Z DEBUG [2/10]: configuring KDC 2020-02-29T07:58:29Z DEBUG Backing up system configuration file '/var/kerberos/krb5kdc/kdc.conf' 2020-02-29T07:58:29Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-02-29T07:58:29Z DEBUG Backing up system configuration file '/etc/krb5.conf' 2020-02-29T07:58:29Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-02-29T07:58:29Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa-server' 2020-02-29T07:58:29Z DEBUG -> Not backing up - '/etc/krb5.conf.d/freeipa-server' doesn't exist 2020-02-29T07:58:29Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa' 2020-02-29T07:58:29Z DEBUG -> Not backing up - '/etc/krb5.conf.d/freeipa' doesn't exist 2020-02-29T07:58:29Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb5.ini' 2020-02-29T07:58:29Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb5.ini' doesn't exist 2020-02-29T07:58:29Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb.con' 2020-02-29T07:58:29Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb.con' doesn't exist 2020-02-29T07:58:29Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krbrealm.con' 2020-02-29T07:58:29Z DEBUG -> Not backing up - '/usr/share/ipa/html/krbrealm.con' doesn't exist 2020-02-29T07:58:29Z DEBUG Starting external process 2020-02-29T07:58:29Z DEBUG args=['/usr/bin/klist', '-V'] 2020-02-29T07:58:29Z DEBUG Process finished, return code=0 2020-02-29T07:58:29Z DEBUG stdout=Kerberos 5 version 1.17 2020-02-29T07:58:29Z DEBUG stderr= 2020-02-29T07:58:29Z DEBUG Backing up system configuration file '/etc/sysconfig/krb5kdc' 2020-02-29T07:58:29Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-02-29T07:58:29Z DEBUG Starting external process 2020-02-29T07:58:29Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-02-29T07:58:29Z DEBUG Process finished, return code=1 2020-02-29T07:58:29Z DEBUG stdout= 2020-02-29T07:58:29Z DEBUG stderr= 2020-02-29T07:58:29Z DEBUG step duration: krb5kdc __configure_instance 0.06 sec 2020-02-29T07:58:29Z DEBUG [3/10]: initialize kerberos container 2020-02-29T07:58:29Z DEBUG Starting external process 2020-02-29T07:58:29Z DEBUG args=['kdb5_util', 'create', '-s', '-r', 'MYDOMAIN.LOCAL', '-x', 'ipa-setup-override-restrictions'] 2020-02-29T07:58:29Z DEBUG Process finished, return code=0 2020-02-29T07:58:29Z DEBUG stdout=Loading random data Initializing database '/var/kerberos/krb5kdc/principal' for realm 'MYDOMAIN.LOCAL', master key name 'K/M@MYDOMAIN.LOCAL' You will be prompted for the database Master Password. It is important that you NOT FORGET this password. Enter KDC database master key: Re-enter KDC database master key to verify: 2020-02-29T07:58:29Z DEBUG stderr= 2020-02-29T07:58:29Z DEBUG step duration: krb5kdc __init_ipa_kdb 0.28 sec 2020-02-29T07:58:29Z DEBUG [4/10]: adding default ACIs 2020-02-29T07:58:29Z DEBUG Starting external process 2020-02-29T07:58:29Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpjloe2546', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:29Z DEBUG Process finished, return code=0 2020-02-29T07:58:29Z DEBUG stdout=add aci: (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) modifying entry "dc=mydomain,dc=local" modify complete add aci: (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) modifying entry "dc=mydomain,dc=local" modify complete add aci: (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=mydomain,dc=local";) modifying entry "cn=etc,dc=mydomain,dc=local" modify complete add aci: (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=mydomain,dc=local";) modifying entry "cn=ipa,cn=etc,dc=mydomain,dc=local" modify complete add aci: (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=mydomain,dc=local";) (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=mydomain,dc=local";) (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=mydomain,dc=local";) (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) modifying entry "cn=accounts,dc=mydomain,dc=local" modify complete add aci: (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=mydomain,dc=local")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=mydomain,dc=local";) modifying entry "cn=services,cn=accounts,dc=mydomain,dc=local" modify complete add aci: (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) modifying entry "cn=services,cn=accounts,dc=mydomain,dc=local" modify complete add aci: (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) modifying entry "cn=computers,cn=accounts,dc=mydomain,dc=local" modify complete add aci: (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) modifying entry "cn=computers,cn=accounts,dc=mydomain,dc=local" modify complete add aci: (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=mydomain,dc=local")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=mydomain,dc=local";) modifying entry "cn=computers,cn=accounts,dc=mydomain,dc=local" modify complete add aci: (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) modifying entry "cn=groups,cn=accounts,dc=mydomain,dc=local" modify complete add aci: (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) modifying entry "cn=hostgroups,cn=accounts,dc=mydomain,dc=local" modify complete add aci: (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) modifying entry "cn=accounts,dc=mydomain,dc=local" modify complete add aci: (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=mydomain,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) modifying entry "dc=mydomain,dc=local" modify complete 2020-02-29T07:58:29Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:29Z DEBUG step duration: krb5kdc __add_default_acis 0.12 sec 2020-02-29T07:58:29Z DEBUG [5/10]: creating a keytab for the directory 2020-02-29T07:58:29Z DEBUG Starting external process 2020-02-29T07:58:29Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL', '-x', 'ipa-setup-override-restrictions'] 2020-02-29T07:58:29Z DEBUG Process finished, return code=0 2020-02-29T07:58:29Z DEBUG stdout=Authenticating as principal root/admin@MYDOMAIN.LOCAL with password. Principal "ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL" created. 2020-02-29T07:58:29Z DEBUG stderr=WARNING: no policy specified for ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL; defaulting to no policy 2020-02-29T07:58:29Z DEBUG Backing up system configuration file '/etc/dirsrv/ds.keytab' 2020-02-29T07:58:29Z DEBUG -> Not backing up - '/etc/dirsrv/ds.keytab' doesn't exist 2020-02-29T07:58:29Z DEBUG Starting external process 2020-02-29T07:58:29Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/dirsrv/ds.keytab ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL', '-x', 'ipa-setup-override-restrictions'] 2020-02-29T07:58:29Z DEBUG Process finished, return code=0 2020-02-29T07:58:29Z DEBUG stdout=Authenticating as principal root/admin@MYDOMAIN.LOCAL with password. Entry for principal ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab. 2020-02-29T07:58:29Z DEBUG stderr= 2020-02-29T07:58:29Z DEBUG step duration: krb5kdc __create_ds_keytab 0.42 sec 2020-02-29T07:58:29Z DEBUG [6/10]: creating a keytab for the machine 2020-02-29T07:58:29Z DEBUG Starting external process 2020-02-29T07:58:29Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey host/vault-ca.mydomain.local@MYDOMAIN.LOCAL', '-x', 'ipa-setup-override-restrictions'] 2020-02-29T07:58:30Z DEBUG Process finished, return code=0 2020-02-29T07:58:30Z DEBUG stdout=Authenticating as principal root/admin@MYDOMAIN.LOCAL with password. Principal "host/vault-ca.mydomain.local@MYDOMAIN.LOCAL" created. 2020-02-29T07:58:30Z DEBUG stderr=WARNING: no policy specified for host/vault-ca.mydomain.local@MYDOMAIN.LOCAL; defaulting to no policy 2020-02-29T07:58:30Z DEBUG Backing up system configuration file '/etc/krb5.keytab' 2020-02-29T07:58:30Z DEBUG -> Not backing up - '/etc/krb5.keytab' doesn't exist 2020-02-29T07:58:30Z DEBUG Starting external process 2020-02-29T07:58:30Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/krb5.keytab host/vault-ca.mydomain.local@MYDOMAIN.LOCAL', '-x', 'ipa-setup-override-restrictions'] 2020-02-29T07:58:30Z DEBUG Process finished, return code=0 2020-02-29T07:58:30Z DEBUG stdout=Authenticating as principal root/admin@MYDOMAIN.LOCAL with password. Entry for principal host/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/vault-ca.mydomain.local@MYDOMAIN.LOCAL with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/krb5.keytab. 2020-02-29T07:58:30Z DEBUG stderr= 2020-02-29T07:58:30Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.aci 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.automember 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.automount 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-02-29T07:58:30Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.batch 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.ca 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.cert 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.config 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.dns 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.group 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-02-29T07:58:30Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.host 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.internal 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.join 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.location 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.migration 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.misc 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.otp 2020-02-29T07:58:30Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.permission 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.ping 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-02-29T07:58:30Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.role 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.schema 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.server 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.service 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.session 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-02-29T07:58:30Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.topology 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.trust 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.user 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.vault 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-02-29T07:58:30Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-02-29T07:58:30Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-02-29T07:58:30Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-02-29T07:58:31Z DEBUG Created connection context.ldap2_139637294540880 2020-02-29T07:58:31Z DEBUG Destroyed connection context.ldap2_139637294540880 2020-02-29T07:58:31Z DEBUG Created connection context.ldap2_139637294540880 2020-02-29T07:58:31Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2020-02-29T07:58:31Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket from SchemaCache 2020-02-29T07:58:31Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket conn= 2020-02-29T07:58:31Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=mydomain,dc=local 2020-02-29T07:58:31Z DEBUG --------------------------------------------- 2020-02-29T07:58:31Z DEBUG Initial value 2020-02-29T07:58:31Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=mydomain,dc=local 2020-02-29T07:58:31Z DEBUG objectClass: 2020-02-29T07:58:31Z DEBUG top 2020-02-29T07:58:31Z DEBUG groupOfNames 2020-02-29T07:58:31Z DEBUG nestedGroup 2020-02-29T07:58:31Z DEBUG ipaobject 2020-02-29T07:58:31Z DEBUG ipahostgroup 2020-02-29T07:58:31Z DEBUG description: 2020-02-29T07:58:31Z DEBUG IPA server hosts 2020-02-29T07:58:31Z DEBUG cn: 2020-02-29T07:58:31Z DEBUG ipaservers 2020-02-29T07:58:31Z DEBUG ipaUniqueID: 2020-02-29T07:58:31Z DEBUG 43d249a4-5ac9-11ea-b0ba-00163e5e6c00 2020-02-29T07:58:31Z DEBUG --------------------------------------------- 2020-02-29T07:58:31Z DEBUG Final value after applying updates 2020-02-29T07:58:31Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=mydomain,dc=local 2020-02-29T07:58:31Z DEBUG objectClass: 2020-02-29T07:58:31Z DEBUG top 2020-02-29T07:58:31Z DEBUG groupOfNames 2020-02-29T07:58:31Z DEBUG nestedGroup 2020-02-29T07:58:31Z DEBUG ipaobject 2020-02-29T07:58:31Z DEBUG ipahostgroup 2020-02-29T07:58:31Z DEBUG description: 2020-02-29T07:58:31Z DEBUG IPA server hosts 2020-02-29T07:58:31Z DEBUG cn: 2020-02-29T07:58:31Z DEBUG ipaservers 2020-02-29T07:58:31Z DEBUG ipaUniqueID: 2020-02-29T07:58:31Z DEBUG 43d249a4-5ac9-11ea-b0ba-00163e5e6c00 2020-02-29T07:58:31Z DEBUG [] 2020-02-29T07:58:31Z DEBUG Updated 0 2020-02-29T07:58:31Z DEBUG Done 2020-02-29T07:58:31Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=mydomain,dc=local 2020-02-29T07:58:31Z DEBUG --------------------------------------------- 2020-02-29T07:58:31Z DEBUG Initial value 2020-02-29T07:58:31Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=mydomain,dc=local 2020-02-29T07:58:31Z DEBUG objectClass: 2020-02-29T07:58:31Z DEBUG top 2020-02-29T07:58:31Z DEBUG groupOfNames 2020-02-29T07:58:31Z DEBUG nestedGroup 2020-02-29T07:58:31Z DEBUG ipaobject 2020-02-29T07:58:31Z DEBUG ipahostgroup 2020-02-29T07:58:31Z DEBUG description: 2020-02-29T07:58:31Z DEBUG IPA server hosts 2020-02-29T07:58:31Z DEBUG cn: 2020-02-29T07:58:31Z DEBUG ipaservers 2020-02-29T07:58:31Z DEBUG ipaUniqueID: 2020-02-29T07:58:31Z DEBUG 43d249a4-5ac9-11ea-b0ba-00163e5e6c00 2020-02-29T07:58:31Z DEBUG add: 'fqdn=localhost.localdomain,cn=computers,cn=accounts,dc=mydomain,dc=local' to member, current value [] 2020-02-29T07:58:31Z DEBUG add: updated value ['fqdn=localhost.localdomain,cn=computers,cn=accounts,dc=mydomain,dc=local'] 2020-02-29T07:58:31Z DEBUG --------------------------------------------- 2020-02-29T07:58:31Z DEBUG Final value after applying updates 2020-02-29T07:58:31Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=mydomain,dc=local 2020-02-29T07:58:31Z DEBUG objectClass: 2020-02-29T07:58:31Z DEBUG top 2020-02-29T07:58:31Z DEBUG groupOfNames 2020-02-29T07:58:31Z DEBUG nestedGroup 2020-02-29T07:58:31Z DEBUG ipaobject 2020-02-29T07:58:31Z DEBUG ipahostgroup 2020-02-29T07:58:31Z DEBUG description: 2020-02-29T07:58:31Z DEBUG IPA server hosts 2020-02-29T07:58:31Z DEBUG cn: 2020-02-29T07:58:31Z DEBUG ipaservers 2020-02-29T07:58:31Z DEBUG ipaUniqueID: 2020-02-29T07:58:31Z DEBUG 43d249a4-5ac9-11ea-b0ba-00163e5e6c00 2020-02-29T07:58:31Z DEBUG member: 2020-02-29T07:58:31Z DEBUG fqdn=localhost.localdomain,cn=computers,cn=accounts,dc=mydomain,dc=local 2020-02-29T07:58:31Z DEBUG [(2, 'member', ['fqdn=localhost.localdomain,cn=computers,cn=accounts,dc=mydomain,dc=local'])] 2020-02-29T07:58:31Z DEBUG Updated 1 2020-02-29T07:58:31Z DEBUG Done 2020-02-29T07:58:31Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-ipaservers_hostgroup.update 0.141 sec 2020-02-29T07:58:31Z DEBUG Destroyed connection context.ldap2_139637294540880 2020-02-29T07:58:31Z DEBUG step duration: krb5kdc __create_host_keytab 1.51 sec 2020-02-29T07:58:31Z DEBUG [7/10]: adding the password extension to the directory 2020-02-29T07:58:31Z DEBUG Starting external process 2020-02-29T07:58:31Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp_9dke1vv', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:31Z DEBUG Process finished, return code=0 2020-02-29T07:58:31Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_pwd_extop add nsslapd-pluginpath: libipa_pwd_extop add nsslapd-plugininitfunc: ipapwd_init add nsslapd-plugintype: extendedop add nsslapd-pluginbetxn: on add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_pwd_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support saving passwords in multiple formats for different consumers (krb5, samba, freeradius, etc.) add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=mydomain,dc=local adding new entry "cn=ipa_pwd_extop,cn=plugins,cn=config" modify complete 2020-02-29T07:58:31Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:31Z DEBUG step duration: krb5kdc __add_pwd_extop_module 0.02 sec 2020-02-29T07:58:31Z DEBUG [8/10]: creating anonymous principal 2020-02-29T07:58:31Z DEBUG Starting external process 2020-02-29T07:58:31Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey WELLKNOWN/ANONYMOUS@MYDOMAIN.LOCAL', '-x', 'ipa-setup-override-restrictions'] 2020-02-29T07:58:31Z DEBUG Process finished, return code=0 2020-02-29T07:58:31Z DEBUG stdout=Authenticating as principal root/admin@MYDOMAIN.LOCAL with password. Principal "WELLKNOWN/ANONYMOUS@MYDOMAIN.LOCAL" created. 2020-02-29T07:58:31Z DEBUG stderr=WARNING: no policy specified for WELLKNOWN/ANONYMOUS@MYDOMAIN.LOCAL; defaulting to no policy 2020-02-29T07:58:31Z DEBUG Starting external process 2020-02-29T07:58:31Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpikjuskhn', '-H', 'ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket', '-Y', 'EXTERNAL'] 2020-02-29T07:58:31Z DEBUG Process finished, return code=0 2020-02-29T07:58:31Z DEBUG stdout=add objectclass: ipaAllowedOperations add aci: (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) add ipaAllowedToPerform;read_keys: cn=ipaservers,cn=hostgroups,cn=accounts,dc=mydomain,dc=local modifying entry "krbPrincipalName=WELLKNOWN/ANONYMOUS@MYDOMAIN.LOCAL,cn=MYDOMAIN.LOCAL,cn=kerberos,dc=mydomain,dc=local" modify complete 2020-02-29T07:58:31Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-02-29T07:58:31Z DEBUG step duration: krb5kdc add_anonymous_principal 0.17 sec 2020-02-29T07:58:31Z DEBUG [9/10]: starting the KDC 2020-02-29T07:58:31Z DEBUG Starting external process 2020-02-29T07:58:31Z DEBUG args=['/bin/systemctl', 'start', 'krb5kdc.service'] 2020-02-29T07:58:31Z DEBUG Process finished, return code=0 2020-02-29T07:58:31Z DEBUG stdout= 2020-02-29T07:58:31Z DEBUG stderr= 2020-02-29T07:58:31Z DEBUG Starting external process 2020-02-29T07:58:31Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2020-02-29T07:58:31Z DEBUG Process finished, return code=0 2020-02-29T07:58:31Z DEBUG stdout=active 2020-02-29T07:58:31Z DEBUG stderr= 2020-02-29T07:58:31Z DEBUG Start of krb5kdc.service complete 2020-02-29T07:58:31Z DEBUG step duration: krb5kdc __start_instance 0.08 sec 2020-02-29T07:58:31Z DEBUG [10/10]: configuring KDC to start on boot 2020-02-29T07:58:31Z DEBUG Starting external process 2020-02-29T07:58:31Z DEBUG args=['/bin/systemctl', 'is-enabled', 'krb5kdc.service'] 2020-02-29T07:58:31Z DEBUG Process finished, return code=1 2020-02-29T07:58:31Z DEBUG stdout=disabled 2020-02-29T07:58:31Z DEBUG stderr= 2020-02-29T07:58:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:31Z DEBUG Starting external process 2020-02-29T07:58:31Z DEBUG args=['/bin/systemctl', 'disable', 'krb5kdc.service'] 2020-02-29T07:58:31Z DEBUG Process finished, return code=0 2020-02-29T07:58:31Z DEBUG stdout= 2020-02-29T07:58:31Z DEBUG stderr= 2020-02-29T07:58:31Z DEBUG step duration: krb5kdc __enable 0.26 sec 2020-02-29T07:58:31Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2020-02-29T07:58:31Z DEBUG service duration: krb5kdc 2.98 sec 2020-02-29T07:58:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:31Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-02-29T07:58:31Z DEBUG Configuring kadmin 2020-02-29T07:58:31Z DEBUG [1/2]: starting kadmin 2020-02-29T07:58:31Z DEBUG Starting external process 2020-02-29T07:58:31Z DEBUG args=['/bin/systemctl', 'is-active', 'kadmin.service'] 2020-02-29T07:58:31Z DEBUG Process finished, return code=3 2020-02-29T07:58:31Z DEBUG stdout=inactive 2020-02-29T07:58:31Z DEBUG stderr= 2020-02-29T07:58:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:31Z DEBUG Starting external process 2020-02-29T07:58:31Z DEBUG args=['/bin/systemctl', 'restart', 'kadmin.service'] 2020-02-29T07:58:32Z DEBUG Process finished, return code=0 2020-02-29T07:58:32Z DEBUG stdout= 2020-02-29T07:58:32Z DEBUG stderr= 2020-02-29T07:58:32Z DEBUG Starting external process 2020-02-29T07:58:32Z DEBUG args=['/bin/systemctl', 'is-active', 'kadmin.service'] 2020-02-29T07:58:32Z DEBUG Process finished, return code=0 2020-02-29T07:58:32Z DEBUG stdout=active 2020-02-29T07:58:32Z DEBUG stderr= 2020-02-29T07:58:32Z DEBUG Restart of kadmin.service complete 2020-02-29T07:58:32Z DEBUG step duration: kadmin __start 0.20 sec 2020-02-29T07:58:32Z DEBUG [2/2]: configuring kadmin to start on boot 2020-02-29T07:58:32Z DEBUG Starting external process 2020-02-29T07:58:32Z DEBUG args=['/bin/systemctl', 'is-enabled', 'kadmin.service'] 2020-02-29T07:58:32Z DEBUG Process finished, return code=1 2020-02-29T07:58:32Z DEBUG stdout=disabled 2020-02-29T07:58:32Z DEBUG stderr= 2020-02-29T07:58:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:32Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:32Z DEBUG Starting external process 2020-02-29T07:58:32Z DEBUG args=['/bin/systemctl', 'disable', 'kadmin.service'] 2020-02-29T07:58:32Z DEBUG Process finished, return code=0 2020-02-29T07:58:32Z DEBUG stdout= 2020-02-29T07:58:32Z DEBUG stderr= 2020-02-29T07:58:32Z DEBUG step duration: kadmin __enable 0.22 sec 2020-02-29T07:58:32Z DEBUG Done configuring kadmin. 2020-02-29T07:58:32Z DEBUG service duration: kadmin 0.42 sec 2020-02-29T07:58:32Z DEBUG Custodia client for '' with promotion no. 2020-02-29T07:58:32Z DEBUG Custodia uses LDAPI. 2020-02-29T07:58:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:32Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-02-29T07:58:32Z DEBUG Configuring ipa-custodia 2020-02-29T07:58:32Z DEBUG [1/5]: Making sure custodia container exists 2020-02-29T07:58:32Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.aci 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.automember 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.automount 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-02-29T07:58:32Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.batch 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.ca 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.cert 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.config 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.dns 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.group 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-02-29T07:58:32Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.host 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.internal 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.join 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.location 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.migration 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.misc 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.otp 2020-02-29T07:58:32Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.permission 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.ping 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-02-29T07:58:32Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.role 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.schema 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.server 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.service 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.session 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-02-29T07:58:32Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.topology 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.trust 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.user 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.vault 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-02-29T07:58:32Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-02-29T07:58:32Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-02-29T07:58:32Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-02-29T07:58:33Z DEBUG Created connection context.ldap2_139637280956624 2020-02-29T07:58:33Z DEBUG Destroyed connection context.ldap2_139637280956624 2020-02-29T07:58:33Z DEBUG Created connection context.ldap2_139637280956624 2020-02-29T07:58:33Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2020-02-29T07:58:33Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket from SchemaCache 2020-02-29T07:58:33Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket conn= 2020-02-29T07:58:33Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=mydomain,dc=local 2020-02-29T07:58:33Z DEBUG --------------------------------------------- 2020-02-29T07:58:33Z DEBUG Initial value 2020-02-29T07:58:33Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=mydomain,dc=local 2020-02-29T07:58:33Z DEBUG objectClass: 2020-02-29T07:58:33Z DEBUG nsContainer 2020-02-29T07:58:33Z DEBUG top 2020-02-29T07:58:33Z DEBUG cn: 2020-02-29T07:58:33Z DEBUG custodia 2020-02-29T07:58:33Z DEBUG --------------------------------------------- 2020-02-29T07:58:33Z DEBUG Final value after applying updates 2020-02-29T07:58:33Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=mydomain,dc=local 2020-02-29T07:58:33Z DEBUG objectClass: 2020-02-29T07:58:33Z DEBUG nsContainer 2020-02-29T07:58:33Z DEBUG top 2020-02-29T07:58:33Z DEBUG cn: 2020-02-29T07:58:33Z DEBUG custodia 2020-02-29T07:58:33Z DEBUG [] 2020-02-29T07:58:33Z DEBUG Updated 0 2020-02-29T07:58:33Z DEBUG Done 2020-02-29T07:58:33Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=mydomain,dc=local 2020-02-29T07:58:33Z DEBUG --------------------------------------------- 2020-02-29T07:58:33Z DEBUG Initial value 2020-02-29T07:58:33Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=mydomain,dc=local 2020-02-29T07:58:33Z DEBUG objectClass: 2020-02-29T07:58:33Z DEBUG nsContainer 2020-02-29T07:58:33Z DEBUG top 2020-02-29T07:58:33Z DEBUG cn: 2020-02-29T07:58:33Z DEBUG dogtag 2020-02-29T07:58:33Z DEBUG --------------------------------------------- 2020-02-29T07:58:33Z DEBUG Final value after applying updates 2020-02-29T07:58:33Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=mydomain,dc=local 2020-02-29T07:58:33Z DEBUG objectClass: 2020-02-29T07:58:33Z DEBUG nsContainer 2020-02-29T07:58:33Z DEBUG top 2020-02-29T07:58:33Z DEBUG cn: 2020-02-29T07:58:33Z DEBUG dogtag 2020-02-29T07:58:33Z DEBUG [] 2020-02-29T07:58:33Z DEBUG Updated 0 2020-02-29T07:58:33Z DEBUG Done 2020-02-29T07:58:33Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-custodia.update 0.137 sec 2020-02-29T07:58:33Z DEBUG Destroyed connection context.ldap2_139637280956624 2020-02-29T07:58:33Z DEBUG step duration: ipa-custodia __create_container 1.16 sec 2020-02-29T07:58:33Z DEBUG [2/5]: Generating ipa-custodia config file 2020-02-29T07:58:33Z DEBUG step duration: ipa-custodia __config_file 0.01 sec 2020-02-29T07:58:33Z DEBUG [3/5]: Generating ipa-custodia keys 2020-02-29T07:58:33Z DEBUG step duration: ipa-custodia __gen_keys 0.28 sec 2020-02-29T07:58:33Z DEBUG [4/5]: starting ipa-custodia 2020-02-29T07:58:33Z DEBUG Starting external process 2020-02-29T07:58:33Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2020-02-29T07:58:33Z DEBUG Process finished, return code=3 2020-02-29T07:58:33Z DEBUG stdout=inactive 2020-02-29T07:58:33Z DEBUG stderr= 2020-02-29T07:58:33Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:33Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:33Z DEBUG Starting external process 2020-02-29T07:58:33Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-custodia.service'] 2020-02-29T07:58:34Z DEBUG Process finished, return code=0 2020-02-29T07:58:34Z DEBUG stdout= 2020-02-29T07:58:34Z DEBUG stderr= 2020-02-29T07:58:34Z DEBUG Starting external process 2020-02-29T07:58:34Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2020-02-29T07:58:34Z DEBUG Process finished, return code=0 2020-02-29T07:58:34Z DEBUG stdout=active 2020-02-29T07:58:34Z DEBUG stderr= 2020-02-29T07:58:34Z DEBUG Restart of ipa-custodia.service complete 2020-02-29T07:58:34Z DEBUG step duration: ipa-custodia __start 0.62 sec 2020-02-29T07:58:34Z DEBUG [5/5]: configuring ipa-custodia to start on boot 2020-02-29T07:58:34Z DEBUG Starting external process 2020-02-29T07:58:34Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ipa-custodia.service'] 2020-02-29T07:58:34Z DEBUG Process finished, return code=1 2020-02-29T07:58:34Z DEBUG stdout=disabled 2020-02-29T07:58:34Z DEBUG stderr= 2020-02-29T07:58:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:34Z DEBUG Starting external process 2020-02-29T07:58:34Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-custodia.service'] 2020-02-29T07:58:34Z DEBUG Process finished, return code=0 2020-02-29T07:58:34Z DEBUG stdout= 2020-02-29T07:58:34Z DEBUG stderr= 2020-02-29T07:58:34Z DEBUG step duration: ipa-custodia __enable 0.26 sec 2020-02-29T07:58:34Z DEBUG Done configuring ipa-custodia. 2020-02-29T07:58:34Z DEBUG service duration: ipa-custodia 2.33 sec 2020-02-29T07:58:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T07:58:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T07:58:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T07:58:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T07:58:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:34Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-02-29T07:58:34Z DEBUG Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes 2020-02-29T07:58:34Z DEBUG [1/29]: configuring certificate server instance 2020-02-29T07:58:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T07:58:34Z DEBUG Contents of pkispawn configuration file (/tmp/tmpka4y9gxy): [CA] pki_admin_cert_file = /root/.dogtag/pki-tomcat/ca_admin.cert pki_admin_cert_request_type = pkcs10 pki_admin_dualkey = False pki_admin_email = root@localhost pki_admin_name = admin pki_admin_nickname = ipa-ca-agent pki_admin_password = XXXXXXXX pki_admin_subject_dn = cn=ipa-ca-agent,O=MYDOMAIN.LOCAL pki_admin_uid = admin pki_audit_group = pkiaudit pki_audit_signing_key_algorithm = SHA256withRSA pki_audit_signing_key_size = 2048 pki_audit_signing_key_type = rsa pki_audit_signing_nickname = auditSigningCert cert-pki-ca pki_audit_signing_signing_algorithm = SHA256withRSA pki_audit_signing_subject_dn = cn=CA Audit,O=MYDOMAIN.LOCAL pki_audit_signing_token = internal pki_backup_keys = True pki_backup_password = XXXXXXXX pki_ca_hostname = vault-ca.mydomain.local pki_ca_port = 443 pki_ca_signing_cert_path = /etc/pki/pki-tomcat/external_ca.cert pki_ca_signing_csr_path = /root/ipa.csr pki_ca_signing_key_algorithm = SHA256withRSA pki_ca_signing_key_size = 3072 pki_ca_signing_key_type = rsa pki_ca_signing_nickname = caSigningCert cert-pki-ca pki_ca_signing_record_create = True pki_ca_signing_serial_number = 1 pki_ca_signing_signing_algorithm = SHA256withRSA pki_ca_signing_subject_dn = CN=Certificate Authority,O=MYDOMAIN.LOCAL pki_ca_signing_token = internal pki_ca_starting_crl_number = 0 pki_cert_chain_nickname = caSigningCert External CA pki_cert_chain_path = /etc/pki/pki-tomcat/external_ca_chain.cert pki_client_admin_cert_p12 = /root/ca-agent.p12 pki_client_database_password = pki_client_database_purge = True pki_client_dir = /root/.dogtag/pki-tomcat pki_client_pkcs12_password = XXXXXXXX pki_configuration_path = /etc/pki pki_default_ocsp_uri = http://ipa-ca.mydomain.local/ca/ocsp pki_dns_domainname = mydomain.local pki_ds_base_dn = o=ipaca pki_ds_bind_dn = cn=Directory Manager pki_ds_database = ipaca pki_ds_hostname = vault-ca.mydomain.local pki_ds_ldap_port = 389 pki_ds_ldaps_port = 636 pki_ds_password = XXXXXXXX pki_ds_remove_data = True pki_ds_secure_connection = False pki_ds_secure_connection_ca_nickname = Directory Server CA certificate pki_ds_secure_connection_ca_pem_file = /etc/ipa/ca.crt pki_enable_proxy = True pki_existing = False pki_external = False pki_external_pkcs12_password = pki_external_pkcs12_path = pki_external_step_two = False pki_group = pkiuser pki_hostname = vault-ca.mydomain.local pki_hsm_enable = False pki_hsm_libfile = pki_hsm_modulename = pki_import_admin_cert = False pki_instance_configuration_path = /etc/pki/pki-tomcat pki_instance_name = pki-tomcat pki_issuing_ca = https://vault-ca.mydomain.local:443 pki_issuing_ca_hostname = vault-ca.mydomain.local pki_issuing_ca_https_port = 443 pki_issuing_ca_uri = https://vault-ca.mydomain.local:443 pki_master_crl_enable = True pki_ocsp_signing_key_algorithm = SHA256withRSA pki_ocsp_signing_key_size = 2048 pki_ocsp_signing_key_type = rsa pki_ocsp_signing_nickname = ocspSigningCert cert-pki-ca pki_ocsp_signing_signing_algorithm = SHA256withRSA pki_ocsp_signing_subject_dn = cn=OCSP Subsystem,O=MYDOMAIN.LOCAL pki_ocsp_signing_token = internal pki_pkcs12_password = pki_pkcs12_path = pki_profiles_in_ldap = True pki_random_serial_numbers_enable = False pki_replica_number_range_end = 100 pki_replica_number_range_start = 1 pki_replication_password = pki_request_number_range_end = 10000000 pki_request_number_range_start = 1 pki_restart_configured_instance = False pki_san_for_server_cert = pki_san_inject = False pki_security_domain_hostname = vault-ca.mydomain.local pki_security_domain_https_port = 443 pki_security_domain_name = IPA pki_security_domain_password = XXXXXXXX pki_security_domain_user = admin pki_self_signed_token = internal pki_serial_number_range_end = 10000000 pki_serial_number_range_start = 1 pki_server_database_password = XXXXXXXX pki_share_db = False pki_skip_configuration = False pki_skip_ds_verify = False pki_skip_installation = False pki_skip_sd_verify = False pki_ssl_server_token = internal pki_sslserver_key_algorithm = SHA256withRSA pki_sslserver_key_size = 2048 pki_sslserver_key_type = rsa pki_sslserver_nickname = Server-Cert cert-pki-ca pki_sslserver_subject_dn = cn=vault-ca.mydomain.local,O=MYDOMAIN.LOCAL pki_sslserver_token = internal pki_status_request_timeout = 15 pki_subordinate = False pki_subordinate_create_new_security_domain = False pki_subsystem = CA pki_subsystem_key_algorithm = SHA256withRSA pki_subsystem_key_size = 2048 pki_subsystem_key_type = rsa pki_subsystem_nickname = subsystemCert cert-pki-ca pki_subsystem_subject_dn = cn=CA Subsystem,O=MYDOMAIN.LOCAL pki_subsystem_token = internal pki_subsystem_type = ca pki_theme_enable = True pki_theme_server_dir = /usr/share/pki/common-ui pki_token_name = internal pki_user = pkiuser 2020-02-29T07:58:34Z DEBUG Starting external process 2020-02-29T07:58:34Z DEBUG args=['/usr/sbin/pkispawn', '-s', 'CA', '-f', '/tmp/tmpka4y9gxy'] 2020-02-29T08:01:03Z DEBUG Process finished, return code=0 2020-02-29T08:01:03Z DEBUG stdout=Installation log: /var/log/pki/pki-ca-spawn.20200229085835.log Loading deployment configuration from /tmp/tmpka4y9gxy. WARNING: The 'pki_ssl_server_token' in [CA] has been deprecated. Use 'pki_sslserver_token' instead. Installing CA into /var/lib/pki/pki-tomcat. ========================================================================== INSTALLATION SUMMARY ========================================================================== Administrator's username: admin Administrator's PKCS #12 file: /root/ca-agent.p12 To check the status of the subsystem: systemctl status pki-tomcatd@pki-tomcat.service To restart the subsystem: systemctl restart pki-tomcatd@pki-tomcat.service The URL for the subsystem is: https://vault-ca.mydomain.local:8443/ca PKI instances will be enabled upon system boot ========================================================================== 2020-02-29T08:01:03Z DEBUG stderr=Notice: Trust flag u is set automatically if the private key is present. Notice: Trust flag u is set automatically if the private key is present. 2020-02-29T08:01:03Z DEBUG completed creating ca instance 2020-02-29T08:01:03Z DEBUG step duration: pki-tomcatd __spawn_instance 148.53 sec 2020-02-29T08:01:03Z DEBUG [2/29]: Add ipa-pki-wait-running 2020-02-29T08:01:03Z DEBUG Starting external process 2020-02-29T08:01:03Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2020-02-29T08:01:03Z DEBUG Process finished, return code=0 2020-02-29T08:01:03Z DEBUG stdout= 2020-02-29T08:01:03Z DEBUG stderr= 2020-02-29T08:01:03Z DEBUG step duration: pki-tomcatd add_ipa_wait 0.21 sec 2020-02-29T08:01:03Z DEBUG [3/29]: reindex attributes 2020-02-29T08:01:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T08:01:03Z DEBUG Creating ipaca reindex task cn=indextask_ipaca_1582963263,cn=index,cn=tasks,cn=config 2020-02-29T08:01:03Z DEBUG Waiting for task... 2020-02-29T08:01:05Z DEBUG Task cn=indextask_ipaca_1582963263,cn=index,cn=tasks,cn=config has finished with exit code 0 2020-02-29T08:01:05Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T08:01:05Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-02-29T08:01:05Z DEBUG step duration: pki-tomcatd reindex_task 2.01 sec 2020-02-29T08:01:05Z DEBUG [4/29]: exporting Dogtag certificate store pin 2020-02-29T08:01:05Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-02-29T08:01:05Z DEBUG step duration: pki-tomcatd create_certstore_passwdfile 0.00 sec 2020-02-29T08:01:05Z DEBUG [5/29]: stopping certificate server instance to update CS.cfg 2020-02-29T08:01:05Z DEBUG Starting external process 2020-02-29T08:01:05Z DEBUG args=['/bin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2020-02-29T08:01:06Z DEBUG Process finished, return code=0 2020-02-29T08:01:06Z DEBUG stdout= 2020-02-29T08:01:06Z DEBUG stderr= 2020-02-29T08:01:06Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2020-02-29T08:01:06Z DEBUG step duration: pki-tomcatd stop_instance 0.89 sec 2020-02-29T08:01:06Z DEBUG [6/29]: backing up CS.cfg 2020-02-29T08:01:06Z DEBUG Starting external process 2020-02-29T08:01:06Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-02-29T08:01:06Z DEBUG Process finished, return code=3 2020-02-29T08:01:06Z DEBUG stdout=inactive 2020-02-29T08:01:06Z DEBUG stderr= 2020-02-29T08:01:06Z DEBUG step duration: pki-tomcatd safe_backup_config 0.02 sec 2020-02-29T08:01:06Z DEBUG [7/29]: disabling nonces 2020-02-29T08:01:06Z DEBUG step duration: pki-tomcatd __disable_nonce 0.00 sec 2020-02-29T08:01:06Z DEBUG [8/29]: set up CRL publishing 2020-02-29T08:01:06Z DEBUG Starting external process 2020-02-29T08:01:06Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-02-29T08:01:06Z DEBUG Process finished, return code=1 2020-02-29T08:01:06Z DEBUG stdout= 2020-02-29T08:01:06Z DEBUG stderr= 2020-02-29T08:01:06Z DEBUG step duration: pki-tomcatd __enable_crl_publish 0.12 sec 2020-02-29T08:01:06Z DEBUG [9/29]: enable PKIX certificate path discovery and validation 2020-02-29T08:01:06Z DEBUG step duration: pki-tomcatd enable_pkix 0.00 sec 2020-02-29T08:01:06Z DEBUG [10/29]: starting certificate server instance 2020-02-29T08:01:06Z DEBUG Starting external process 2020-02-29T08:01:06Z DEBUG args=['/bin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2020-02-29T08:01:23Z DEBUG Process finished, return code=0 2020-02-29T08:01:23Z DEBUG stdout= 2020-02-29T08:01:23Z DEBUG stderr= 2020-02-29T08:01:23Z DEBUG Starting external process 2020-02-29T08:01:23Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-02-29T08:01:23Z DEBUG Process finished, return code=0 2020-02-29T08:01:23Z DEBUG stdout=active 2020-02-29T08:01:23Z DEBUG stderr= 2020-02-29T08:01:23Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2020-02-29T08:01:23Z DEBUG waiting for port: 8080 2020-02-29T08:01:23Z DEBUG SUCCESS: port: 8080 2020-02-29T08:01:23Z DEBUG waiting for port: 8443 2020-02-29T08:01:23Z DEBUG SUCCESS: port: 8443 2020-02-29T08:01:23Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2020-02-29T08:01:23Z DEBUG step duration: pki-tomcatd start_instance 17.20 sec 2020-02-29T08:01:23Z DEBUG [11/29]: configure certmonger for renewals 2020-02-29T08:01:23Z DEBUG Starting external process 2020-02-29T08:01:23Z DEBUG args=['/bin/systemctl', 'enable', 'certmonger.service'] 2020-02-29T08:01:23Z DEBUG Process finished, return code=0 2020-02-29T08:01:23Z DEBUG stdout= 2020-02-29T08:01:23Z DEBUG stderr=Created symlink /etc/systemd/system/multi-user.target.wants/certmonger.service → /usr/lib/systemd/system/certmonger.service. 2020-02-29T08:01:23Z DEBUG Starting external process 2020-02-29T08:01:23Z DEBUG args=['/bin/systemctl', 'is-active', 'dbus.service'] 2020-02-29T08:01:23Z DEBUG Process finished, return code=0 2020-02-29T08:01:23Z DEBUG stdout=active 2020-02-29T08:01:23Z DEBUG stderr= 2020-02-29T08:01:23Z DEBUG Starting external process 2020-02-29T08:01:23Z DEBUG args=['/bin/systemctl', 'start', 'certmonger.service'] 2020-02-29T08:01:24Z DEBUG Process finished, return code=0 2020-02-29T08:01:24Z DEBUG stdout= 2020-02-29T08:01:24Z DEBUG stderr= 2020-02-29T08:01:24Z DEBUG Starting external process 2020-02-29T08:01:24Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2020-02-29T08:01:24Z DEBUG Process finished, return code=0 2020-02-29T08:01:24Z DEBUG stdout=active 2020-02-29T08:01:24Z DEBUG stderr= 2020-02-29T08:01:24Z DEBUG Start of certmonger.service complete 2020-02-29T08:01:25Z DEBUG step duration: pki-tomcatd configure_certmonger_renewal 1.34 sec 2020-02-29T08:01:25Z DEBUG [12/29]: requesting RA certificate from CA 2020-02-29T08:01:25Z DEBUG Starting external process 2020-02-29T08:01:25Z DEBUG args=['/usr/bin/openssl', 'pkcs7', '-inform', 'DER', '-print_certs', '-out', '/var/lib/ipa/tmpd4e_8cjw'] 2020-02-29T08:01:25Z DEBUG Process finished, return code=0 2020-02-29T08:01:25Z DEBUG stdout= 2020-02-29T08:01:25Z DEBUG stderr= 2020-02-29T08:01:25Z DEBUG Starting external process 2020-02-29T08:01:25Z DEBUG args=['/usr/bin/openssl', 'pkcs12', '-nokeys', '-clcerts', '-in', '/root/ca-agent.p12', '-out', '/var/lib/ipa/tmpdi2ncg4s', '-passin', 'file:/tmp/tmpz7jy0bs_'] 2020-02-29T08:01:25Z DEBUG Process finished, return code=0 2020-02-29T08:01:25Z DEBUG stdout= 2020-02-29T08:01:25Z DEBUG stderr= 2020-02-29T08:01:25Z DEBUG Starting external process 2020-02-29T08:01:25Z DEBUG args=['/usr/bin/openssl', 'pkcs12', '-nocerts', '-in', '/root/ca-agent.p12', '-out', '/var/lib/ipa/tmpv93t90gr', '-passin', 'file:/tmp/tmpqnj7ytog', '-nodes'] 2020-02-29T08:01:26Z DEBUG Process finished, return code=0 2020-02-29T08:01:26Z DEBUG stdout= 2020-02-29T08:01:26Z DEBUG stderr= 2020-02-29T08:01:27Z DEBUG certmonger request is in state dbus.String('NEWLY_ADDED_READING_CERT', variant_level=1) 2020-02-29T08:01:32Z DEBUG certmonger request is in state dbus.String('GENERATING_CSR', variant_level=1) 2020-02-29T08:01:37Z DEBUG certmonger request is in state dbus.String('SUBMITTING', variant_level=1) 2020-02-29T08:01:42Z DEBUG certmonger request is in state dbus.String('SUBMITTING', variant_level=1) 2020-02-29T08:01:47Z DEBUG certmonger request is in state dbus.String('SUBMITTING', variant_level=1) 2020-02-29T08:01:52Z DEBUG certmonger request is in state dbus.String('SUBMITTING', variant_level=1) 2020-02-29T08:01:57Z DEBUG wait_for_request raised request timed out 2020-02-29T08:01:57Z DEBUG Cert request 20200229080127 failed: TIMEOUT (None) 2020-02-29T08:01:57Z DEBUG 20200229080127 not in final state, continue waiting 2020-02-29T08:02:07Z DEBUG certmonger request is in state dbus.String('MONITORING', variant_level=1) 2020-02-29T08:02:07Z DEBUG Cert request 20200229080127 was successful 2020-02-29T08:02:07Z DEBUG Starting external process 2020-02-29T08:02:07Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-02-29T08:02:07Z DEBUG Process finished, return code=1 2020-02-29T08:02:07Z DEBUG stdout= 2020-02-29T08:02:07Z DEBUG stderr= 2020-02-29T08:02:07Z DEBUG Starting external process 2020-02-29T08:02:07Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-02-29T08:02:07Z DEBUG Process finished, return code=1 2020-02-29T08:02:07Z DEBUG stdout= 2020-02-29T08:02:07Z DEBUG stderr= 2020-02-29T08:02:07Z DEBUG step duration: pki-tomcatd __request_ra_certificate 42.31 sec 2020-02-29T08:02:07Z DEBUG [13/29]: setting audit signing renewal to 2 years 2020-02-29T08:02:07Z DEBUG caSignedLogCert.cfg profile validity range is 720 2020-02-29T08:02:07Z DEBUG step duration: pki-tomcatd set_audit_renewal 0.00 sec 2020-02-29T08:02:07Z DEBUG [14/29]: restarting certificate server 2020-02-29T08:02:07Z DEBUG Starting external process 2020-02-29T08:02:07Z DEBUG args=['/bin/systemctl', 'restart', 'pki-tomcatd@pki-tomcat.service'] 2020-02-29T08:02:28Z DEBUG Process finished, return code=0 2020-02-29T08:02:28Z DEBUG stdout= 2020-02-29T08:02:28Z DEBUG stderr= 2020-02-29T08:02:28Z DEBUG Starting external process 2020-02-29T08:02:28Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-02-29T08:02:28Z DEBUG Process finished, return code=0 2020-02-29T08:02:28Z DEBUG stdout=active 2020-02-29T08:02:28Z DEBUG stderr= 2020-02-29T08:02:28Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2020-02-29T08:02:28Z DEBUG waiting for port: 8080 2020-02-29T08:02:28Z DEBUG SUCCESS: port: 8080 2020-02-29T08:02:28Z DEBUG waiting for port: 8443 2020-02-29T08:02:28Z DEBUG SUCCESS: port: 8443 2020-02-29T08:02:28Z DEBUG Restart of pki-tomcatd@pki-tomcat.service complete 2020-02-29T08:02:28Z DEBUG step duration: pki-tomcatd restart_instance 21.06 sec 2020-02-29T08:02:28Z DEBUG [15/29]: publishing the CA certificate 2020-02-29T08:02:28Z DEBUG step duration: pki-tomcatd __export_ca_chain 0.05 sec 2020-02-29T08:02:28Z DEBUG [16/29]: adding RA agent as a trusted user 2020-02-29T08:02:28Z DEBUG Created connection context.ldap2_139637281410512 2020-02-29T08:02:28Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket from SchemaCache 2020-02-29T08:02:28Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket conn= 2020-02-29T08:02:28Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Certificate Manager Agents,ou=groups,o=ipaca member_attr=uniqueMember 2020-02-29T08:02:28Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Registration Manager Agents,ou=groups,o=ipaca member_attr=uniqueMember 2020-02-29T08:02:28Z DEBUG Destroyed connection context.ldap2_139637281410512 2020-02-29T08:02:28Z DEBUG step duration: pki-tomcatd __create_ca_agent 0.22 sec 2020-02-29T08:02:28Z DEBUG [17/29]: authorizing RA to modify profiles 2020-02-29T08:02:28Z DEBUG step duration: pki-tomcatd configure_profiles_acl 0.02 sec 2020-02-29T08:02:28Z DEBUG [18/29]: authorizing RA to manage lightweight CAs 2020-02-29T08:02:28Z DEBUG step duration: pki-tomcatd configure_lightweight_ca_acls 0.03 sec 2020-02-29T08:02:28Z DEBUG [19/29]: Ensure lightweight CAs container exists 2020-02-29T08:02:28Z DEBUG Created connection context.ldap2_139637284299536 2020-02-29T08:02:28Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket from SchemaCache 2020-02-29T08:02:28Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-MYDOMAIN-LOCAL.socket conn= 2020-02-29T08:02:28Z DEBUG Destroyed connection context.ldap2_139637284299536 2020-02-29T08:02:28Z DEBUG step duration: pki-tomcatd ensure_lightweight_cas_container 0.20 sec 2020-02-29T08:02:28Z DEBUG [20/29]: configure certificate renewals 2020-02-29T08:02:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T08:02:49Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-02-29T08:03:14Z DEBUG Traceback (most recent call last): File "/usr/lib/python3.7/site-packages/ipaserver/install/service.py", line 603, in start_creation run_step(full_msg, method) File "/usr/lib/python3.7/site-packages/ipaserver/install/service.py", line 589, in run_step method() File "/usr/lib/python3.7/site-packages/ipaserver/install/dogtaginstance.py", line 344, in configure_renewal profile=self.tracking_reqs[nickname], File "/usr/lib/python3.7/site-packages/ipalib/install/certmonger.py", line 521, in start_tracking result = cm.obj_if.add_request(params) File "/usr/lib64/python3.7/site-packages/dbus/proxies.py", line 145, in __call__ **keywords) File "/usr/lib64/python3.7/site-packages/dbus/connection.py", line 651, in call_blocking message, timeout) dbus.exceptions.DBusException: org.freedesktop.DBus.Error.NoReply: Did not receive a reply. Possible causes include: the remote application did not send a reply, the message bus security policy blocked the reply, the reply timeout expired, or the network connection was broken. 2020-02-29T08:03:14Z DEBUG [error] DBusException: org.freedesktop.DBus.Error.NoReply: Did not receive a reply. Possible causes include: the remote application did not send a reply, the message bus security policy blocked the reply, the reply timeout expired, or the network connection was broken. 2020-02-29T08:03:14Z DEBUG Removing /root/.dogtag/pki-tomcat/ca 2020-02-29T08:03:14Z DEBUG File "/usr/lib/python3.7/site-packages/ipapython/admintool.py", line 179, in execute return_value = self.run() File "/usr/lib/python3.7/site-packages/ipapython/install/cli.py", line 340, in run return cfgr.run() File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 360, in run return self.execute() File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 386, in execute for rval in self._executor(): File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 431, in __runner exc_handler(exc_info) File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 460, in _handle_execute_exception self._handle_exception(exc_info) File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 450, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python3.7/site-packages/six.py", line 693, in reraise raise value File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 421, in __runner step() File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 418, in step = lambda: next(self.__gen) File "/usr/lib/python3.7/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) File "/usr/lib/python3.7/site-packages/six.py", line 693, in reraise raise value File "/usr/lib/python3.7/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 655, in _configure next(executor) File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 431, in __runner exc_handler(exc_info) File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 460, in _handle_execute_exception self._handle_exception(exc_info) File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 518, in _handle_exception self.__parent._handle_exception(exc_info) File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 450, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python3.7/site-packages/six.py", line 693, in reraise raise value File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 515, in _handle_exception super(ComponentBase, self)._handle_exception(exc_info) File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 450, in _handle_exception six.reraise(*exc_info) File "/usr/lib/python3.7/site-packages/six.py", line 693, in reraise raise value File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 421, in __runner step() File "/usr/lib/python3.7/site-packages/ipapython/install/core.py", line 418, in step = lambda: next(self.__gen) File "/usr/lib/python3.7/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from six.reraise(*exc_info) File "/usr/lib/python3.7/site-packages/six.py", line 693, in reraise raise value File "/usr/lib/python3.7/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from value = gen.send(prev_value) File "/usr/lib/python3.7/site-packages/ipapython/install/common.py", line 65, in _install for unused in self._installer(self.parent): File "/usr/lib/python3.7/site-packages/ipaserver/install/server/__init__.py", line 557, in main master_install(self) File "/usr/lib/python3.7/site-packages/ipaserver/install/server/install.py", line 255, in decorated func(installer) File "/usr/lib/python3.7/site-packages/ipaserver/install/server/install.py", line 870, in install ca.install_step_0(False, None, options, custodia=custodia) File "/usr/lib/python3.7/site-packages/ipaserver/install/ca.py", line 355, in install_step_0 pki_config_override=options.pki_config_override, File "/usr/lib/python3.7/site-packages/ipaserver/install/cainstance.py", line 480, in configure_instance self.start_creation(runtime=runtime) File "/usr/lib/python3.7/site-packages/ipaserver/install/service.py", line 603, in start_creation run_step(full_msg, method) File "/usr/lib/python3.7/site-packages/ipaserver/install/service.py", line 589, in run_step method() File "/usr/lib/python3.7/site-packages/ipaserver/install/dogtaginstance.py", line 344, in configure_renewal profile=self.tracking_reqs[nickname], File "/usr/lib/python3.7/site-packages/ipalib/install/certmonger.py", line 521, in start_tracking result = cm.obj_if.add_request(params) File "/usr/lib64/python3.7/site-packages/dbus/proxies.py", line 145, in __call__ **keywords) File "/usr/lib64/python3.7/site-packages/dbus/connection.py", line 651, in call_blocking message, timeout) 2020-02-29T08:03:14Z DEBUG The ipa-server-install command failed, exception: DBusException: org.freedesktop.DBus.Error.NoReply: Did not receive a reply. Possible causes include: the remote application did not send a reply, the message bus security policy blocked the reply, the reply timeout expired, or the network connection was broken. 2020-02-29T08:03:14Z ERROR org.freedesktop.DBus.Error.NoReply: Did not receive a reply. Possible causes include: the remote application did not send a reply, the message bus security policy blocked the reply, the reply timeout expired, or the network connection was broken. 2020-02-29T08:03:14Z ERROR The ipa-server-install command failed. See /var/log/ipaserver-install.log for more information