2018-02-15T06:40:31Z DEBUG Logging to /var/log/ipareplica-install.log 2018-02-15T06:40:31Z DEBUG IPA version 4.5.4-10.el7 2018-02-15T06:40:31Z DEBUG Searching for an interface of IP address: ::1 2018-02-15T06:40:31Z DEBUG Testing local IP address: ::1/ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff (interface: lo) 2018-02-15T06:40:31Z DEBUG Starting external process 2018-02-15T06:40:31Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-15T06:40:31Z DEBUG Process finished, return code=0 2018-02-15T06:40:31Z DEBUG stdout= 2018-02-15T06:40:31Z DEBUG stderr= 2018-02-15T06:40:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:31Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:40:31Z DEBUG httpd is not configured 2018-02-15T06:40:31Z DEBUG kadmin is not configured 2018-02-15T06:40:31Z DEBUG dirsrv is not configured 2018-02-15T06:40:31Z DEBUG pki-tomcatd is not configured 2018-02-15T06:40:31Z DEBUG install is not configured 2018-02-15T06:40:31Z DEBUG krb5kdc is not configured 2018-02-15T06:40:31Z DEBUG ntpd is not configured 2018-02-15T06:40:31Z DEBUG named is not configured 2018-02-15T06:40:31Z DEBUG filestore is tracking no files 2018-02-15T06:40:31Z DEBUG Starting external process 2018-02-15T06:40:31Z DEBUG args=/usr/sbin/httpd -t -D DUMP_VHOSTS 2018-02-15T06:40:31Z DEBUG Process finished, return code=0 2018-02-15T06:40:31Z DEBUG stdout=VirtualHost configuration: *:8443 replica3.pytest.test (/etc/httpd/conf.d/nss.conf:81) 2018-02-15T06:40:31Z DEBUG stderr= 2018-02-15T06:40:31Z DEBUG Starting external process 2018-02-15T06:40:31Z DEBUG args=/bin/systemctl is-enabled chronyd.service 2018-02-15T06:40:31Z DEBUG Process finished, return code=0 2018-02-15T06:40:31Z DEBUG stdout=enabled 2018-02-15T06:40:31Z DEBUG stderr= 2018-02-15T06:40:31Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2018-02-15T06:40:31Z DEBUG Configuring client side components 2018-02-15T06:40:31Z DEBUG Starting external process 2018-02-15T06:40:31Z DEBUG args=/usr/sbin/ipa-client-install --unattended --no-ntp --domain pytest.test --realm PYTEST.TEST --principal admin 2018-02-15T06:40:39Z DEBUG Process finished, return code=0 2018-02-15T06:40:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:39Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:40:39Z DEBUG importing all plugin modules in ipaserver.plugins... 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.aci 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.automember 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.automount 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.baseldap 2018-02-15T06:40:39Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.baseuser 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.batch 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.ca 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.caacl 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.cert 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.certmap 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.certprofile 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.config 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.delegation 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.dns 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.dogtag 2018-02-15T06:40:39Z DEBUG skipping plugin module ipaserver.plugins.dogtag: dogtag not selected as RA plugin 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.group 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.hbac 2018-02-15T06:40:39Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.hbactest 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.host 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.idrange 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.idviews 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.internal 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.join 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.ldap2 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.location 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.migration 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.misc 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.netgroup 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.otp 2018-02-15T06:40:39Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.otptoken 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.passwd 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.permission 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.ping 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.pkinit 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.privilege 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.rabase 2018-02-15T06:40:39Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.role 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.schema 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.selfservice 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.server 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.serverrole 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.serverroles 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.service 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.session 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.stageuser 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.sudo 2018-02-15T06:40:39Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.sudorule 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.topology 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.trust 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.user 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.vault 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.virtual 2018-02-15T06:40:39Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.whoami 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2018-02-15T06:40:39Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.dns 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2018-02-15T06:40:39Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2018-02-15T06:40:40Z DEBUG Check if replica3.pytest.test is a primary hostname for localhost 2018-02-15T06:40:40Z DEBUG Primary hostname for localhost: replica3.pytest.test 2018-02-15T06:40:40Z DEBUG Search DNS for replica3.pytest.test 2018-02-15T06:40:40Z DEBUG Check if replica3.pytest.test is not a CNAME 2018-02-15T06:40:40Z DEBUG Found reverse name: replica3.pytest.test 2018-02-15T06:40:40Z DEBUG Check if master.pytest.test is a primary hostname for localhost 2018-02-15T06:40:40Z DEBUG Search DNS for master.pytest.test 2018-02-15T06:40:41Z DEBUG importing all plugin modules in ipaserver.plugins... 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.aci 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.automember 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.automount 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.baseldap 2018-02-15T06:40:41Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.baseuser 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.batch 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.ca 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.caacl 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.cert 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.certmap 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.certprofile 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.config 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.delegation 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.dns 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.dogtag 2018-02-15T06:40:41Z DEBUG skipping plugin module ipaserver.plugins.dogtag: dogtag not selected as RA plugin 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.group 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.hbac 2018-02-15T06:40:41Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.hbactest 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.host 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.idrange 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.idviews 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.internal 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.join 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.ldap2 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.location 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.migration 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.misc 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.netgroup 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.otp 2018-02-15T06:40:41Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.otptoken 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.passwd 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.permission 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.ping 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.pkinit 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.privilege 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.rabase 2018-02-15T06:40:41Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.role 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.schema 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.selfservice 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.server 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.serverrole 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.serverroles 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.service 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.session 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.stageuser 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.sudo 2018-02-15T06:40:41Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.sudorule 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.topology 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.trust 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.user 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.vault 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.virtual 2018-02-15T06:40:41Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.whoami 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2018-02-15T06:40:41Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.dns 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2018-02-15T06:40:41Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2018-02-15T06:40:42Z DEBUG Error retrieving cookie from the persistent storage: expected string or buffer 2018-02-15T06:40:42Z DEBUG failed to find session_cookie in persistent storage for principal 'host/replica3.pytest.test@PYTEST.TEST' 2018-02-15T06:40:42Z INFO trying https://master.pytest.test/ipa/json 2018-02-15T06:40:42Z DEBUG New HTTP connection (master.pytest.test) 2018-02-15T06:40:42Z DEBUG received Set-Cookie ()'['ipa_session=MagBearerToken=7%2bI4GGgGL8fS4aU%2fI8dl0IN3oVdO%2fZ9iSnueMNKeyEeujlcUqoWIaCLvmu94TGumt7dRw7uKSXTpHnR2lOHlRUX1dyJIjhJ39anL1tZ8cvrAOviQTxHYqLkNrBgjr7HtD%2fmQGr9e5wpYyUwcFZW4zAVeNxoWROJ2PXTEq5PrASZemjJDQDz1ISz8JAAKWTeLXOlmzCAqZAYXJAdCp9jpMdSbMcnHxkbcEwyQ0feUdMGv6cniyJUjrw9Oqq6fFnngm%2fxNpdSVJ58iOSkJXClKlg%3d%3d;path=/ipa;httponly;secure;']' 2018-02-15T06:40:42Z DEBUG storing cookie 'ipa_session=MagBearerToken=7%2bI4GGgGL8fS4aU%2fI8dl0IN3oVdO%2fZ9iSnueMNKeyEeujlcUqoWIaCLvmu94TGumt7dRw7uKSXTpHnR2lOHlRUX1dyJIjhJ39anL1tZ8cvrAOviQTxHYqLkNrBgjr7HtD%2fmQGr9e5wpYyUwcFZW4zAVeNxoWROJ2PXTEq5PrASZemjJDQDz1ISz8JAAKWTeLXOlmzCAqZAYXJAdCp9jpMdSbMcnHxkbcEwyQ0feUdMGv6cniyJUjrw9Oqq6fFnngm%2fxNpdSVJ58iOSkJXClKlg%3d%3d;' for principal host/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:40:42Z DEBUG Created connection context.jsonclient_140099990489040 2018-02-15T06:40:42Z INFO [try 1]: Forwarding 'env' to json server 'https://master.pytest.test/ipa/json' 2018-02-15T06:40:42Z DEBUG HTTP connection keep-alive (master.pytest.test) 2018-02-15T06:40:42Z DEBUG received Set-Cookie ()'['ipa_session=MagBearerToken=5ywIxgpwM2r%2bZM48SpxxG1DhNHvtD5%2fGVrRyddaHAxhJWav5V2dpLSiuQgmO3j81300aoOe%2bQFdDTHRS4%2fTcPA4jaqTCIdsaHsIhjsuWOkBEKlxlBK2huhLZewuICQyEqn4pIGdx6oZBbf4fjUvtsqtUke5GGJAGgrAoRcORaBM5lDcedGOBbr8t%2bm%2fqSZ70JIPq6ieQL%2b%2bB4oXD24Mn%2fXosrdSX%2fUnFpXBAhOMsItCetE8b5Qjy1jaJQiF8kHuEDaoGEH3UAR4kPPWjsQqMng%3d%3d;path=/ipa;httponly;secure;']' 2018-02-15T06:40:42Z DEBUG storing cookie 'ipa_session=MagBearerToken=5ywIxgpwM2r%2bZM48SpxxG1DhNHvtD5%2fGVrRyddaHAxhJWav5V2dpLSiuQgmO3j81300aoOe%2bQFdDTHRS4%2fTcPA4jaqTCIdsaHsIhjsuWOkBEKlxlBK2huhLZewuICQyEqn4pIGdx6oZBbf4fjUvtsqtUke5GGJAGgrAoRcORaBM5lDcedGOBbr8t%2bm%2fqSZ70JIPq6ieQL%2b%2bB4oXD24Mn%2fXosrdSX%2fUnFpXBAhOMsItCetE8b5Qjy1jaJQiF8kHuEDaoGEH3UAR4kPPWjsQqMng%3d%3d;' for principal host/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:40:42Z INFO [try 1]: Forwarding 'env' to json server 'https://master.pytest.test/ipa/json' 2018-02-15T06:40:42Z DEBUG HTTP connection keep-alive (master.pytest.test) 2018-02-15T06:40:42Z DEBUG received Set-Cookie ()'['ipa_session=MagBearerToken=YSvE0EI%2bplXk5LM3HJ5i9VetRy6iP085%2bSpaiZYQzjx%2fJNY%2fygvo8xt8mWS6Lflf1Qz4COwM7Z2PtS5b8mzqMmzp2nmFl0W27f77yy2vj5mdsykJbHz8IM7i5UZZLlCxYQKbzoQ2msr%2b2jbletloyC96Gg4tPZmrryzqFFBSGQX9LFiYT512GUCH856yYSRO5ewCBmfHMHCpbMTOw25yeVStVS3VATBkZ5dlxOlGfJSPVm2wH8SM1bcUhG9vFB%2f2jna2URjaKd1pHqgWym90Kg%3d%3d;path=/ipa;httponly;secure;']' 2018-02-15T06:40:42Z DEBUG storing cookie 'ipa_session=MagBearerToken=YSvE0EI%2bplXk5LM3HJ5i9VetRy6iP085%2bSpaiZYQzjx%2fJNY%2fygvo8xt8mWS6Lflf1Qz4COwM7Z2PtS5b8mzqMmzp2nmFl0W27f77yy2vj5mdsykJbHz8IM7i5UZZLlCxYQKbzoQ2msr%2b2jbletloyC96Gg4tPZmrryzqFFBSGQX9LFiYT512GUCH856yYSRO5ewCBmfHMHCpbMTOw25yeVStVS3VATBkZ5dlxOlGfJSPVm2wH8SM1bcUhG9vFB%2f2jna2URjaKd1pHqgWym90Kg%3d%3d;' for principal host/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:40:42Z DEBUG Destroyed connection context.jsonclient_140099990489040 2018-02-15T06:40:42Z DEBUG Created connection context.ldap2_140100000171856 2018-02-15T06:40:42Z DEBUG flushing ldaps://master.pytest.test from SchemaCache 2018-02-15T06:40:42Z DEBUG retrieving schema for SchemaCache url=ldaps://master.pytest.test conn= 2018-02-15T06:40:43Z DEBUG raw: domainlevel_get(version=u'2.228') 2018-02-15T06:40:43Z DEBUG domainlevel_get(version=u'2.228') 2018-02-15T06:40:43Z DEBUG raw: hostgroup_find(None, cn=u'ipaservers', version=u'2.228', host=[u'replica3.pytest.test']) 2018-02-15T06:40:43Z DEBUG hostgroup_find(None, cn=u'ipaservers', all=False, raw=False, version=u'2.228', no_members=True, pkey_only=False, host=(u'replica3.pytest.test',)) 2018-02-15T06:40:43Z DEBUG KRB5CCNAME set to None 2018-02-15T06:40:43Z DEBUG Failed to find default ccache: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639053): No Kerberos credentials available (default cache: KEYRING:persistent:0) 2018-02-15T06:40:43Z DEBUG Initializing principal admin@PYTEST.TEST using password 2018-02-15T06:40:43Z DEBUG Starting external process 2018-02-15T06:40:43Z DEBUG args=/usr/bin/kinit admin@PYTEST.TEST -c /tmp/tmpskLvcD 2018-02-15T06:40:43Z DEBUG Process finished, return code=0 2018-02-15T06:40:43Z DEBUG stdout=Password for admin@PYTEST.TEST: 2018-02-15T06:40:43Z DEBUG stderr= 2018-02-15T06:40:43Z DEBUG Destroyed connection context.ldap2_140100000171856 2018-02-15T06:40:43Z DEBUG Created connection context.ldap2_140100000171856 2018-02-15T06:40:43Z DEBUG raw: hostgroup_show(u'ipaservers', rights=True, all=True, version=u'2.228') 2018-02-15T06:40:43Z DEBUG hostgroup_show(u'ipaservers', rights=True, all=True, raw=False, version=u'2.228', no_members=False) 2018-02-15T06:40:43Z DEBUG flushing ldaps://master.pytest.test from SchemaCache 2018-02-15T06:40:43Z DEBUG retrieving schema for SchemaCache url=ldaps://master.pytest.test conn= 2018-02-15T06:40:43Z DEBUG Destroyed connection context.ldap2_140100000171856 2018-02-15T06:40:43Z DEBUG Created connection context.ldap2_140100000171856 2018-02-15T06:40:43Z DEBUG flushing ldaps://master.pytest.test from SchemaCache 2018-02-15T06:40:43Z DEBUG retrieving schema for SchemaCache url=ldaps://master.pytest.test conn= 2018-02-15T06:40:44Z DEBUG Check forward/reverse DNS resolution 2018-02-15T06:40:50Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:40:50Z DEBUG raw: dns_is_enabled(version=u'2.228') 2018-02-15T06:40:50Z DEBUG dns_is_enabled(version=u'2.228') 2018-02-15T06:40:50Z DEBUG Destroyed connection context.ldap2_140100000171856 2018-02-15T06:40:50Z DEBUG Starting external process 2018-02-15T06:40:50Z DEBUG args=/usr/sbin/ipa-replica-conncheck --master master.pytest.test --auto-master-check --realm PYTEST.TEST --hostname replica3.pytest.test --principal admin --password XXXXXXXX --ca-cert-file /etc/ipa/ca.crt 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout= 2018-02-15T06:40:54Z DEBUG stderr=Check connection from replica to remote master 'master.pytest.test': Directory Service: Unsecure port (389): OK Directory Service: Secure port (636): OK Kerberos KDC: TCP (88): OK Kerberos Kpasswd: TCP (464): OK HTTP Server: Unsecure port (80): OK HTTP Server: Secure port (443): OK The following list of ports use UDP protocoland would need to be checked manually: Kerberos KDC: UDP (88): SKIPPED Kerberos Kpasswd: UDP (464): SKIPPED Connection from replica to master is OK. Start listening on required ports for remote master check Get credentials to log in to remote master Check RPC connection to remote master trying https://master.pytest.test/ipa/json [try 1]: Forwarding 'ping/1' to json server 'https://master.pytest.test/ipa/json' Execute check on remote master [try 1]: Forwarding 'server_conncheck' to json server 'https://master.pytest.test/ipa/json' Check connection from master to remote replica 'replica3.pytest.test': Directory Service: Unsecure port (389): OK Directory Service: Secure port (636): OK Kerberos KDC: TCP (88): OK Kerberos KDC: UDP (88): OK Kerberos Kpasswd: TCP (464): OK Kerberos Kpasswd: UDP (464): OK HTTP Server: Unsecure port (80): OK HTTP Server: Secure port (443): OK Connection from master to replica is OK. 2018-02-15T06:40:54Z DEBUG Created connection context.ldap2_140100000171856 2018-02-15T06:40:54Z DEBUG raw: hostgroup_add_member(u'ipaservers', version=u'2.228', host=[u'replica3.pytest.test']) 2018-02-15T06:40:54Z DEBUG hostgroup_add_member(u'ipaservers', all=False, raw=False, version=u'2.228', no_members=False, host=(u'replica3.pytest.test',)) 2018-02-15T06:40:54Z DEBUG add_entry_to_group: dn=fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test group_dn=cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test member_attr=member 2018-02-15T06:40:54Z DEBUG flushing ldaps://master.pytest.test from SchemaCache 2018-02-15T06:40:54Z DEBUG retrieving schema for SchemaCache url=ldaps://master.pytest.test conn= 2018-02-15T06:40:54Z DEBUG Destroyed connection context.ldap2_140100000171856 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl start messagebus.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout= 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl is-active messagebus.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout=active 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl restart certmonger.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout= 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl is-active certmonger.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout=active 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl enable certmonger.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout= 2018-02-15T06:40:54Z DEBUG stderr=Created symlink from /etc/systemd/system/multi-user.target.wants/certmonger.service to /usr/lib/systemd/system/certmonger.service. 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl is-enabled chronyd.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout=enabled 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl is-active chronyd.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout=active 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:54Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:54Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl stop chronyd.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout= 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl disable chronyd.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout= 2018-02-15T06:40:54Z DEBUG stderr=Removed symlink /etc/systemd/system/multi-user.target.wants/chronyd.service. 2018-02-15T06:40:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:54Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:40:54Z DEBUG Configuring NTP daemon (ntpd) 2018-02-15T06:40:54Z DEBUG [1/4]: stopping ntpd 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl is-active ntpd.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=3 2018-02-15T06:40:54Z DEBUG stdout=inactive 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:54Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl stop ntpd.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout= 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG duration: 0 seconds 2018-02-15T06:40:54Z DEBUG [2/4]: writing configuration 2018-02-15T06:40:54Z DEBUG Backing up system configuration file '/etc/ntp.conf' 2018-02-15T06:40:54Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:40:54Z DEBUG Backing up system configuration file '/etc/sysconfig/ntpd' 2018-02-15T06:40:54Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:40:54Z DEBUG duration: 0 seconds 2018-02-15T06:40:54Z DEBUG [3/4]: configuring ntpd to start on boot 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl is-enabled ntpd.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=1 2018-02-15T06:40:54Z DEBUG stdout=disabled 2018-02-15T06:40:54Z DEBUG stderr= 2018-02-15T06:40:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:54Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:54Z DEBUG Starting external process 2018-02-15T06:40:54Z DEBUG args=/bin/systemctl enable ntpd.service 2018-02-15T06:40:54Z DEBUG Process finished, return code=0 2018-02-15T06:40:54Z DEBUG stdout= 2018-02-15T06:40:54Z DEBUG stderr=Created symlink from /etc/systemd/system/multi-user.target.wants/ntpd.service to /usr/lib/systemd/system/ntpd.service. 2018-02-15T06:40:54Z DEBUG duration: 0 seconds 2018-02-15T06:40:55Z DEBUG [4/4]: starting ntpd 2018-02-15T06:40:55Z DEBUG Starting external process 2018-02-15T06:40:55Z DEBUG args=/bin/systemctl start ntpd.service 2018-02-15T06:40:55Z DEBUG Process finished, return code=0 2018-02-15T06:40:55Z DEBUG stdout= 2018-02-15T06:40:55Z DEBUG stderr= 2018-02-15T06:40:55Z DEBUG Starting external process 2018-02-15T06:40:55Z DEBUG args=/bin/systemctl is-active ntpd.service 2018-02-15T06:40:55Z DEBUG Process finished, return code=0 2018-02-15T06:40:55Z DEBUG stdout=active 2018-02-15T06:40:55Z DEBUG stderr= 2018-02-15T06:40:55Z DEBUG duration: 0 seconds 2018-02-15T06:40:55Z DEBUG Done configuring NTP daemon (ntpd). 2018-02-15T06:40:55Z DEBUG Created connection context.ldap2_140100000171856 2018-02-15T06:40:55Z DEBUG flushing ldaps://master.pytest.test from SchemaCache 2018-02-15T06:40:55Z DEBUG retrieving schema for SchemaCache url=ldaps://master.pytest.test conn= 2018-02-15T06:40:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:55Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:40:55Z DEBUG Configuring directory server (dirsrv). Estimated time: 30 seconds 2018-02-15T06:40:55Z DEBUG [1/42]: creating directory server instance 2018-02-15T06:40:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:55Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:40:55Z DEBUG Backing up system configuration file '/etc/sysconfig/dirsrv' 2018-02-15T06:40:55Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:40:55Z DEBUG dn: dc=pytest,dc=test objectClass: top objectClass: domain objectClass: pilotObject dc: pytest info: IPA V2.0 2018-02-15T06:40:55Z DEBUG writing inf template 2018-02-15T06:40:55Z DEBUG [General] FullMachineName= replica3.pytest.test SuiteSpotUserID= dirsrv SuiteSpotGroup= dirsrv ServerRoot= /usr/lib64/dirsrv [slapd] ServerPort= 389 ServerIdentifier= PYTEST-TEST Suffix= dc=pytest,dc=test RootDN= cn=Directory Manager InstallLdifFile= /var/lib/dirsrv/boot.ldif inst_dir= /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:40:55Z DEBUG calling setup-ds.pl 2018-02-15T06:40:55Z DEBUG Starting external process 2018-02-15T06:40:55Z DEBUG args=/usr/sbin/setup-ds.pl --silent --logfile - -f /tmp/tmpKHC62R 2018-02-15T06:41:02Z DEBUG Process finished, return code=0 2018-02-15T06:41:02Z DEBUG stdout=[18/02/15:01:41:02] - [Setup] Info Your new DS instance 'PYTEST-TEST' was successfully created. Your new DS instance 'PYTEST-TEST' was successfully created. [18/02/15:01:41:02] - [Setup] Success Exiting . . . Log file is '-' Exiting . . . Log file is '-' 2018-02-15T06:41:02Z DEBUG stderr= 2018-02-15T06:41:02Z DEBUG completed creating DS instance 2018-02-15T06:41:02Z DEBUG duration: 6 seconds 2018-02-15T06:41:02Z DEBUG [2/42]: enabling ldapi 2018-02-15T06:41:02Z DEBUG Starting external process 2018-02-15T06:41:02Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpWDaxHe -H ldap://localhost -x -D cn=Directory Manager -y /tmp/tmpFEtQI8 2018-02-15T06:41:02Z DEBUG Process finished, return code=0 2018-02-15T06:41:02Z DEBUG stdout=replace nsslapd-ldapilisten: on modifying entry "cn=config" modify complete 2018-02-15T06:41:02Z DEBUG stderr=ldap_initialize( ldap://localhost:389/??base ) 2018-02-15T06:41:02Z DEBUG duration: 0 seconds 2018-02-15T06:41:02Z DEBUG [3/42]: configure autobind for root 2018-02-15T06:41:02Z DEBUG Starting external process 2018-02-15T06:41:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/root-autobind.ldif -H ldap://localhost -x -D cn=Directory Manager -y /tmp/tmpyVLxPy 2018-02-15T06:41:02Z DEBUG Process finished, return code=0 2018-02-15T06:41:02Z DEBUG stdout=add objectClass: extensibleObject top add cn: root-autobind add uidNumber: 0 add gidNumber: 0 adding new entry "cn=root-autobind,cn=config" modify complete replace nsslapd-ldapiautobind: on modifying entry "cn=config" modify complete replace nsslapd-ldapimaptoentries: on modifying entry "cn=config" modify complete 2018-02-15T06:41:02Z DEBUG stderr=ldap_initialize( ldap://localhost:389/??base ) 2018-02-15T06:41:02Z DEBUG duration: 0 seconds 2018-02-15T06:41:02Z DEBUG [4/42]: stopping directory server 2018-02-15T06:41:02Z DEBUG Starting external process 2018-02-15T06:41:02Z DEBUG args=/bin/systemctl stop dirsrv@PYTEST-TEST.service 2018-02-15T06:41:04Z DEBUG Process finished, return code=0 2018-02-15T06:41:04Z DEBUG stdout= 2018-02-15T06:41:04Z DEBUG stderr= 2018-02-15T06:41:04Z DEBUG duration: 2 seconds 2018-02-15T06:41:04Z DEBUG [5/42]: updating configuration in dse.ldif 2018-02-15T06:41:04Z DEBUG duration: 0 seconds 2018-02-15T06:41:04Z DEBUG [6/42]: starting directory server 2018-02-15T06:41:04Z DEBUG Starting external process 2018-02-15T06:41:04Z DEBUG args=/bin/systemctl start dirsrv@PYTEST-TEST.service 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout= 2018-02-15T06:41:09Z DEBUG stderr= 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/bin/systemctl is-active dirsrv@PYTEST-TEST.service 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=active 2018-02-15T06:41:09Z DEBUG stderr= 2018-02-15T06:41:09Z DEBUG wait_for_open_ports: localhost [389] timeout 300 2018-02-15T06:41:09Z DEBUG waiting for port: 389 2018-02-15T06:41:09Z DEBUG SUCCESS: port: 389 2018-02-15T06:41:09Z DEBUG Created connection context.ldap2_140100023575440 2018-02-15T06:41:09Z DEBUG duration: 4 seconds 2018-02-15T06:41:09Z DEBUG [7/42]: adding default schema 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [8/42]: enabling memberof plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/memberof-conf.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=replace nsslapd-pluginenabled: on add memberofgroupattr: memberUser add memberofgroupattr: memberHost modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [9/42]: enabling winsync plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/ipa-winsync-conf.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa-winsync add nsslapd-pluginpath: libipa_winsync add nsslapd-plugininitfunc: ipa_winsync_plugin_init add nsslapd-pluginDescription: Allows IPA to work with the DS windows sync feature add nsslapd-pluginid: ipa-winsync add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-plugin-depends-on-type: database add ipaWinSyncRealmFilter: (objectclass=krbRealmContainer) add ipaWinSyncRealmAttr: cn add ipaWinSyncNewEntryFilter: (cn=ipaConfig) add ipaWinSyncNewUserOCAttr: ipauserobjectclasses add ipaWinSyncUserFlatten: true add ipaWinsyncHomeDirAttr: ipaHomesRootDir add ipaWinsyncLoginShellAttr: ipaDefaultLoginShell add ipaWinSyncDefaultGroupAttr: ipaDefaultPrimaryGroup add ipaWinSyncDefaultGroupFilter: (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) add ipaWinSyncAcctDisable: both add ipaWinSyncForceSync: true add ipaWinSyncUserAttr: uidNumber -1 gidNumber -1 adding new entry "cn=ipa-winsync,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [10/42]: configuring replication version plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/version-conf.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Version Replication add nsslapd-pluginpath: libipa_repl_version add nsslapd-plugininitfunc: repl_version_plugin_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: off add nsslapd-pluginid: ipa_repl_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Replication version plugin add nsslapd-plugin-depends-on-type: database add nsslapd-plugin-depends-on-named: Multimaster Replication Plugin adding new entry "cn=IPA Version Replication,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [11/42]: enabling IPA enrollment plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpCbm1u6 -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_enrollment_extop add nsslapd-pluginpath: libipa_enrollment_extop add nsslapd-plugininitfunc: ipaenrollment_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_enrollment_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Enroll hosts into the IPA domain add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=pytest,dc=test adding new entry "cn=ipa_enrollment_extop,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [12/42]: configuring uniqueness plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmphql_WT -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: krbPrincipalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbPrincipalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=pytest,dc=test add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test add uniqueness-across-all-subtrees: on adding new entry "cn=krbPrincipalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: krbCanonicalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbCanonicalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=pytest,dc=test add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test add uniqueness-across-all-subtrees: on adding new entry "cn=krbCanonicalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: netgroup uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=ng,cn=alt,dc=pytest,dc=test add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values adding new entry "cn=netgroup uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: ipaUniqueID uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: ipaUniqueID add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=pytest,dc=test add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test add uniqueness-across-all-subtrees: on adding new entry "cn=ipaUniqueID uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: sudorule name uniqueness add nsslapd-pluginDescription: Enforce unique attribute values add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=sudorules,cn=sudo,dc=pytest,dc=test add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project adding new entry "cn=sudorule name uniqueness,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [13/42]: configuring uuid plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/uuid-conf.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA UUID add nsslapd-pluginpath: libipa_uuid add nsslapd-plugininitfunc: ipauuid_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipauuid_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA UUID plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA UUID,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpouVl9W -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectclass: top extensibleObject add cn: IPA Unique IDs add ipaUuidAttr: ipaUniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (|(objectclass=ipaObject)(objectclass=ipaAssociation)) add ipaUuidScope: dc=pytest,dc=test add ipaUuidEnforce: TRUE adding new entry "cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: IPK11 Unique IDs add ipaUuidAttr: ipk11UniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (objectclass=ipk11Object) add ipaUuidScope: dc=pytest,dc=test add ipaUuidEnforce: FALSE adding new entry "cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [14/42]: configuring modrdn plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/modrdn-conf.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA MODRDN add nsslapd-pluginpath: libipa_modrdn add nsslapd-plugininitfunc: ipamodrdn_init add nsslapd-plugintype: betxnpostoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipamodrdn_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA MODRDN plugin add nsslapd-plugin-depends-on-type: database add nsslapd-pluginPrecedence: 60 adding new entry "cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmptNWGyp -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectclass: top extensibleObject add cn: Kerberos Principal Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbPrincipalName add ipaModRDNsuffix: @PYTEST.TEST add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=pytest,dc=test adding new entry "cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: Kerberos Canonical Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbCanonicalName add ipaModRDNsuffix: @PYTEST.TEST add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=pytest,dc=test adding new entry "cn=Kerberos Canonical Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [15/42]: configuring DNS plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/ipa-dns-conf.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectclass: top nsslapdPlugin extensibleObject add cn: IPA DNS add nsslapd-plugindescription: IPA DNS support plugin add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_dns add nsslapd-plugininitfunc: ipadns_init add nsslapd-pluginpath: libipa_dns.so add nsslapd-plugintype: preoperation add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-pluginversion: 1.0 add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA DNS,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [16/42]: enabling entryUSN plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/entryusn.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=replace nsslapd-entryusn-global: on modifying entry "cn=config" modify complete replace nsslapd-entryusn-import-initval: next modifying entry "cn=config" modify complete replace nsslapd-pluginenabled: on modifying entry "cn=USN,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [17/42]: configuring lockout plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/lockout-conf.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Lockout add nsslapd-pluginpath: libipa_lockout add nsslapd-plugininitfunc: ipalockout_init add nsslapd-plugintype: object add nsslapd-pluginenabled: on add nsslapd-pluginid: ipalockout_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Lockout plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA Lockout,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [18/42]: configuring topology plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpfmzz1Z -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: IPA Topology Configuration add nsslapd-pluginPath: libtopology add nsslapd-pluginInitfunc: ipa_topo_init add nsslapd-pluginType: object add nsslapd-pluginEnabled: on add nsslapd-topo-plugin-shared-config-base: cn=ipa,cn=etc,dc=pytest,dc=test add nsslapd-topo-plugin-shared-replica-root: dc=pytest,dc=test o=ipaca add nsslapd-topo-plugin-shared-binddngroup: cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test add nsslapd-topo-plugin-startup-delay: 20 add nsslapd-pluginId: none add nsslapd-plugin-depends-on-named: ldbm database Multimaster Replication Plugin add nsslapd-pluginVersion: 1.0 add nsslapd-pluginVendor: none add nsslapd-pluginDescription: none adding new entry "cn=IPA Topology Configuration,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [19/42]: creating indices 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/indices.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add objectClass: top nsIndex add cn: krbPrincipalName add nsSystemIndex: false add nsIndexType: eq sub add nsMatchingRule: caseIgnoreIA5Match caseExactIA5Match adding new entry "cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: ou add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: carLicense add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: title add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: manager add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: secretary add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: displayname add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add nsIndexType: sub modifying entry "cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: uidnumber add nsSystemIndex: false add nsIndexType: eq add nsMatchingRule: integerOrderingMatch adding new entry "cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: gidnumber add nsSystemIndex: false add nsIndexType: eq add nsMatchingRule: integerOrderingMatch adding new entry "cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete replace nsIndexType: eq pres modifying entry "cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete replace nsIndexType: eq pres modifying entry "cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add ObjectClass: top nsIndex add cn: fqdn add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add ObjectClass: top nsIndex add cn: macAddress add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberHost add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberUser add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: sourcehost add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberservice add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: managedby add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberallowcmd add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberdenycmd add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipasudorunas add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipasudorunasgroup add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: automountkey add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipakrbprincipalalias add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipauniqueid add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaMemberCa add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaMemberCertProfile add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: userCertificate add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipalocation add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: krbCanonicalName add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: description add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: l add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsOsVersion add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsHardwarePlatform add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsHostLocation add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [20/42]: enabling referential integrity plugin 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/referint-conf.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=replace nsslapd-pluginenabled: on modifying entry "cn=referential integrity postoperation,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [21/42]: configuring certmap.conf 2018-02-15T06:41:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:41:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:41:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [22/42]: configure new location for managed entries 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpoxuNF3 -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test modifying entry "cn=Managed Entries,cn=plugins,cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [23/42]: configure dirsrv ccache 2018-02-15T06:41:09Z DEBUG Backing up system configuration file '/etc/sysconfig/dirsrv' 2018-02-15T06:41:09Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout= 2018-02-15T06:41:09Z DEBUG stderr= 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/sbin/restorecon /etc/sysconfig/dirsrv 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout= 2018-02-15T06:41:09Z DEBUG stderr= 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [24/42]: enabling SASL mapping fallback 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpyqZZA0 -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:09Z DEBUG Process finished, return code=0 2018-02-15T06:41:09Z DEBUG stdout=replace nsslapd-sasl-mapping-fallback: on modifying entry "cn=config" modify complete 2018-02-15T06:41:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:09Z DEBUG duration: 0 seconds 2018-02-15T06:41:09Z DEBUG [25/42]: restarting directory server 2018-02-15T06:41:09Z DEBUG Destroyed connection context.ldap2_140100023575440 2018-02-15T06:41:09Z DEBUG Starting external process 2018-02-15T06:41:09Z DEBUG args=/bin/systemctl --system daemon-reload 2018-02-15T06:41:10Z DEBUG Process finished, return code=0 2018-02-15T06:41:10Z DEBUG stdout= 2018-02-15T06:41:10Z DEBUG stderr= 2018-02-15T06:41:10Z DEBUG Starting external process 2018-02-15T06:41:10Z DEBUG args=/bin/systemctl restart dirsrv@PYTEST-TEST.service 2018-02-15T06:41:16Z DEBUG Process finished, return code=0 2018-02-15T06:41:16Z DEBUG stdout= 2018-02-15T06:41:16Z DEBUG stderr= 2018-02-15T06:41:16Z DEBUG Starting external process 2018-02-15T06:41:16Z DEBUG args=/bin/systemctl is-active dirsrv@PYTEST-TEST.service 2018-02-15T06:41:16Z DEBUG Process finished, return code=0 2018-02-15T06:41:16Z DEBUG stdout=active 2018-02-15T06:41:16Z DEBUG stderr= 2018-02-15T06:41:16Z DEBUG wait_for_open_ports: localhost [389] timeout 300 2018-02-15T06:41:16Z DEBUG waiting for port: 389 2018-02-15T06:41:16Z DEBUG SUCCESS: port: 389 2018-02-15T06:41:16Z DEBUG Starting external process 2018-02-15T06:41:16Z DEBUG args=/bin/systemctl is-active dirsrv@PYTEST-TEST.service 2018-02-15T06:41:16Z DEBUG Process finished, return code=0 2018-02-15T06:41:16Z DEBUG stdout=active 2018-02-15T06:41:16Z DEBUG stderr= 2018-02-15T06:41:16Z DEBUG Created connection context.ldap2_140100023575440 2018-02-15T06:41:16Z DEBUG duration: 6 seconds 2018-02-15T06:41:16Z DEBUG [26/42]: creating DS keytab 2018-02-15T06:41:16Z DEBUG raw: service_add(u'ldap/replica3.pytest.test@PYTEST.TEST', force=True, version=u'2.228') 2018-02-15T06:41:16Z DEBUG service_add(ipapython.kerberos.Principal('ldap/replica3.pytest.test@PYTEST.TEST'), force=True, all=False, raw=False, version=u'2.228', no_members=False) 2018-02-15T06:41:16Z DEBUG raw: host_show(u'replica3.pytest.test', version=u'2.228') 2018-02-15T06:41:16Z DEBUG host_show(u'replica3.pytest.test', rights=False, all=False, raw=False, version=u'2.228', no_members=False) 2018-02-15T06:41:16Z DEBUG Backing up system configuration file '/etc/dirsrv/ds.keytab' 2018-02-15T06:41:16Z DEBUG -> Not backing up - '/etc/dirsrv/ds.keytab' doesn't exist 2018-02-15T06:41:16Z DEBUG Starting external process 2018-02-15T06:41:16Z DEBUG args=/usr/sbin/ipa-getkeytab -k /etc/dirsrv/ds.keytab -p ldap/replica3.pytest.test@PYTEST.TEST -H ldaps://master.pytest.test 2018-02-15T06:41:16Z DEBUG Process finished, return code=0 2018-02-15T06:41:16Z DEBUG stdout= 2018-02-15T06:41:16Z DEBUG stderr=Keytab successfully retrieved and stored in: /etc/dirsrv/ds.keytab 2018-02-15T06:41:16Z DEBUG duration: 0 seconds 2018-02-15T06:41:16Z DEBUG [27/42]: ignore time skew for initial replication 2018-02-15T06:41:16Z DEBUG Starting external process 2018-02-15T06:41:16Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpShYGCe -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:16Z DEBUG Process finished, return code=0 2018-02-15T06:41:16Z DEBUG stdout=replace nsslapd-ignore-time-skew: on modifying entry "cn=config" modify complete 2018-02-15T06:41:16Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:16Z DEBUG duration: 0 seconds 2018-02-15T06:41:16Z DEBUG [28/42]: setting up initial replication 2018-02-15T06:41:16Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-PYTEST-TEST.socket conn= 2018-02-15T06:41:17Z DEBUG Destroyed connection context.ldap2_140100023575440 2018-02-15T06:41:17Z DEBUG Starting external process 2018-02-15T06:41:17Z DEBUG args=/bin/systemctl --system daemon-reload 2018-02-15T06:41:17Z DEBUG Process finished, return code=0 2018-02-15T06:41:17Z DEBUG stdout= 2018-02-15T06:41:17Z DEBUG stderr= 2018-02-15T06:41:17Z DEBUG Starting external process 2018-02-15T06:41:17Z DEBUG args=/bin/systemctl restart dirsrv@PYTEST-TEST.service 2018-02-15T06:41:23Z DEBUG Process finished, return code=0 2018-02-15T06:41:23Z DEBUG stdout= 2018-02-15T06:41:23Z DEBUG stderr= 2018-02-15T06:41:23Z DEBUG Created connection context.ldap2_140100023575440 2018-02-15T06:41:23Z DEBUG Fetching nsDS5ReplicaId from master [attempt 1/5] 2018-02-15T06:41:23Z DEBUG retrieving schema for SchemaCache url=ldap://master.pytest.test:389 conn= 2018-02-15T06:41:24Z DEBUG Successfully updated nsDS5ReplicaId. 2018-02-15T06:41:29Z DEBUG duration: 12 seconds 2018-02-15T06:41:29Z DEBUG [29/42]: prevent time skew after initial replication 2018-02-15T06:41:29Z DEBUG Starting external process 2018-02-15T06:41:29Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpoPNo_F -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:29Z DEBUG Process finished, return code=0 2018-02-15T06:41:29Z DEBUG stdout=replace nsslapd-ignore-time-skew: off modifying entry "cn=config" modify complete 2018-02-15T06:41:29Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:29Z DEBUG duration: 0 seconds 2018-02-15T06:41:29Z DEBUG [30/42]: adding sasl mappings to the directory 2018-02-15T06:41:29Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket from SchemaCache 2018-02-15T06:41:29Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket conn= 2018-02-15T06:41:29Z DEBUG duration: 0 seconds 2018-02-15T06:41:29Z DEBUG [31/42]: updating schema 2018-02-15T06:41:29Z DEBUG Starting external process 2018-02-15T06:41:29Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/schema-update.ldif -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:29Z DEBUG Process finished, return code=0 2018-02-15T06:41:29Z DEBUG stdout=add objectClasses: ( 2.16.840.1.113730.3.2.41 NAME 'nsslapdPlugin' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsslapd-pluginPath $ nsslapd-pluginInitFunc $ nsslapd-pluginType $ nsslapd-pluginId $ nsslapd-pluginVersion $ nsslapd-pluginVendor $ nsslapd-pluginDescription $ nsslapd-pluginEnabled ) MAY ( nsslapd-pluginConfigArea $ nsslapd-plugin-depends-on-type ) X-ORIGIN 'Netscape Directory Server' ) ( 2.16.840.1.113730.3.2.317 NAME 'nsSaslMapping' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsSaslMapRegexString $ nsSaslMapBaseDNTemplate $ nsSaslMapFilterTemplate ) MAY ( nsSaslMapPriority ) X-ORIGIN 'Netscape Directory Server' ) modifying entry "cn=schema" modify complete 2018-02-15T06:41:29Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:29Z DEBUG duration: 0 seconds 2018-02-15T06:41:29Z DEBUG [32/42]: setting Auto Member configuration 2018-02-15T06:41:29Z DEBUG Starting external process 2018-02-15T06:41:29Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpabO3QM -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:29Z DEBUG Process finished, return code=0 2018-02-15T06:41:29Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=automember,cn=etc,dc=pytest,dc=test modifying entry "cn=Auto Membership Plugin,cn=plugins,cn=config" modify complete 2018-02-15T06:41:29Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:29Z DEBUG duration: 0 seconds 2018-02-15T06:41:29Z DEBUG [33/42]: enabling S4U2Proxy delegation 2018-02-15T06:41:29Z DEBUG duration: 0 seconds 2018-02-15T06:41:29Z DEBUG [34/42]: initializing group membership 2018-02-15T06:41:29Z DEBUG duration: 0 seconds 2018-02-15T06:41:29Z DEBUG [35/42]: adding master entry 2018-02-15T06:41:29Z DEBUG Starting external process 2018-02-15T06:41:29Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpjRsikW -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:29Z DEBUG Process finished, return code=0 2018-02-15T06:41:29Z DEBUG stdout=add objectclass: top nsContainer ipaReplTopoManagedServer ipaConfigObject ipaSupportedDomainLevelConfig add cn: replica3.pytest.test add ipaReplTopoManagedSuffix: dc=pytest,dc=test add ipaMinDomainLevel: 0 add ipaMaxDomainLevel: 1 adding new entry "cn=replica3.pytest.test,cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test" modify complete 2018-02-15T06:41:29Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:29Z DEBUG duration: 0 seconds 2018-02-15T06:41:29Z DEBUG [36/42]: initializing domain level 2018-02-15T06:41:29Z DEBUG duration: 0 seconds 2018-02-15T06:41:29Z DEBUG [37/42]: configuring Posix uid/gid generation 2018-02-15T06:41:29Z DEBUG Starting external process 2018-02-15T06:41:29Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpVqT1EC -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:29Z DEBUG Process finished, return code=0 2018-02-15T06:41:29Z DEBUG stdout=add objectclass: top extensibleObject add cn: Posix IDs add dnaType: uidNumber gidNumber add dnaNextValue: 1101 add dnaMaxValue: 1100 add dnaMagicRegen: -1 add dnaFilter: (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) add dnaScope: dc=pytest,dc=test add dnaThreshold: 500 add dnaSharedCfgDN: cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test add dnaExcludeScope: cn=provisioning,dc=pytest,dc=test adding new entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete replace nsslapd-pluginEnabled: on modifying entry "cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete 2018-02-15T06:41:29Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:29Z DEBUG duration: 0 seconds 2018-02-15T06:41:29Z DEBUG [38/42]: adding replication acis 2018-02-15T06:41:29Z DEBUG Starting external process 2018-02-15T06:41:29Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpZzKqIi -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:30Z DEBUG Process finished, return code=0 2018-02-15T06:41:30Z DEBUG stdout=add aci: (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) modifying entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete add aci: (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) modifying entry "cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add aci: (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) modifying entry "cn=tasks,cn=config" modify complete 2018-02-15T06:41:30Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:30Z DEBUG duration: 0 seconds 2018-02-15T06:41:30Z DEBUG [39/42]: activating sidgen plugin 2018-02-15T06:41:30Z DEBUG Starting external process 2018-02-15T06:41:30Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpW24jwC -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:30Z DEBUG Process finished, return code=0 2018-02-15T06:41:30Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA SIDGEN add nsslapd-pluginpath: libipa_sidgen add nsslapd-plugininitfunc: ipa_sidgen_init add nsslapd-plugintype: postoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_sidgen_postop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA SIDGEN post operation add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=pytest,dc=test adding new entry "cn=IPA SIDGEN,cn=plugins,cn=config" modify complete 2018-02-15T06:41:30Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:30Z DEBUG duration: 0 seconds 2018-02-15T06:41:30Z DEBUG [40/42]: activating extdom plugin 2018-02-15T06:41:30Z DEBUG Starting external process 2018-02-15T06:41:30Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpDUGJhK -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:30Z DEBUG Process finished, return code=0 2018-02-15T06:41:30Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_extdom_extop add nsslapd-pluginpath: libipa_extdom_extop add nsslapd-plugininitfunc: ipa_extdom_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_extdom_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support resolving IDs in trusted domains to names and back add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=pytest,dc=test adding new entry "cn=ipa_extdom_extop,cn=plugins,cn=config" modify complete 2018-02-15T06:41:30Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:30Z DEBUG duration: 0 seconds 2018-02-15T06:41:30Z DEBUG [41/42]: tuning directory server 2018-02-15T06:41:30Z DEBUG Starting external process 2018-02-15T06:41:30Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-15T06:41:30Z DEBUG Process finished, return code=0 2018-02-15T06:41:30Z DEBUG stdout= 2018-02-15T06:41:30Z DEBUG stderr= 2018-02-15T06:41:30Z DEBUG Starting external process 2018-02-15T06:41:30Z DEBUG args=/sbin/restorecon /etc/sysconfig/dirsrv.systemd 2018-02-15T06:41:30Z DEBUG Process finished, return code=0 2018-02-15T06:41:30Z DEBUG stdout= 2018-02-15T06:41:30Z DEBUG stderr= 2018-02-15T06:41:30Z DEBUG Starting external process 2018-02-15T06:41:30Z DEBUG args=/bin/systemctl --system daemon-reload 2018-02-15T06:41:30Z DEBUG Process finished, return code=0 2018-02-15T06:41:30Z DEBUG stdout= 2018-02-15T06:41:30Z DEBUG stderr= 2018-02-15T06:41:30Z DEBUG Destroyed connection context.ldap2_140100023575440 2018-02-15T06:41:30Z DEBUG Starting external process 2018-02-15T06:41:30Z DEBUG args=/bin/systemctl --system daemon-reload 2018-02-15T06:41:30Z DEBUG Process finished, return code=0 2018-02-15T06:41:30Z DEBUG stdout= 2018-02-15T06:41:30Z DEBUG stderr= 2018-02-15T06:41:30Z DEBUG Starting external process 2018-02-15T06:41:30Z DEBUG args=/bin/systemctl restart dirsrv@PYTEST-TEST.service 2018-02-15T06:41:38Z DEBUG Process finished, return code=0 2018-02-15T06:41:38Z DEBUG stdout= 2018-02-15T06:41:38Z DEBUG stderr= 2018-02-15T06:41:38Z DEBUG Starting external process 2018-02-15T06:41:38Z DEBUG args=/bin/systemctl is-active dirsrv@PYTEST-TEST.service 2018-02-15T06:41:38Z DEBUG Process finished, return code=0 2018-02-15T06:41:38Z DEBUG stdout=active 2018-02-15T06:41:38Z DEBUG stderr= 2018-02-15T06:41:38Z DEBUG wait_for_open_ports: localhost [389] timeout 300 2018-02-15T06:41:38Z DEBUG waiting for port: 389 2018-02-15T06:41:38Z DEBUG SUCCESS: port: 389 2018-02-15T06:41:38Z DEBUG Starting external process 2018-02-15T06:41:38Z DEBUG args=/bin/systemctl is-active dirsrv@PYTEST-TEST.service 2018-02-15T06:41:38Z DEBUG Process finished, return code=0 2018-02-15T06:41:38Z DEBUG stdout=active 2018-02-15T06:41:38Z DEBUG stderr= 2018-02-15T06:41:38Z DEBUG Created connection context.ldap2_140100023575440 2018-02-15T06:41:38Z DEBUG Starting external process 2018-02-15T06:41:38Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpjjZZOX -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:38Z DEBUG Process finished, return code=0 2018-02-15T06:41:38Z DEBUG stdout=replace nsslapd-maxdescriptors: 8192 replace nsslapd-reservedescriptors: 64 modifying entry "cn=config" modify complete 2018-02-15T06:41:38Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:38Z DEBUG duration: 8 seconds 2018-02-15T06:41:38Z DEBUG [42/42]: configuring directory to start on boot 2018-02-15T06:41:38Z DEBUG Starting external process 2018-02-15T06:41:38Z DEBUG args=/bin/systemctl is-enabled dirsrv@PYTEST-TEST.service 2018-02-15T06:41:38Z DEBUG Process finished, return code=0 2018-02-15T06:41:38Z DEBUG stdout=enabled 2018-02-15T06:41:38Z DEBUG stderr= 2018-02-15T06:41:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:38Z DEBUG Starting external process 2018-02-15T06:41:38Z DEBUG args=/bin/systemctl disable dirsrv@PYTEST-TEST.service 2018-02-15T06:41:38Z DEBUG Process finished, return code=0 2018-02-15T06:41:38Z DEBUG stdout= 2018-02-15T06:41:38Z DEBUG stderr=Removed symlink /etc/systemd/system/multi-user.target.wants/dirsrv@PYTEST-TEST.service. Removed symlink /etc/systemd/system/dirsrv.target.wants/dirsrv@PYTEST-TEST.service. 2018-02-15T06:41:38Z DEBUG duration: 0 seconds 2018-02-15T06:41:38Z DEBUG Done configuring directory server (dirsrv). 2018-02-15T06:41:38Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket from SchemaCache 2018-02-15T06:41:38Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket conn= 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG raw: dnszone_show(u'131.41.19.10.in-addr.arpa.', version=u'2.228') 2018-02-15T06:41:39Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:41:39Z DEBUG raw: dnszone_show(u'41.19.10.in-addr.arpa.', version=u'2.228') 2018-02-15T06:41:39Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:41:39Z DEBUG raw: dnszone_show(u'19.10.in-addr.arpa.', version=u'2.228') 2018-02-15T06:41:39Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:41:39Z DEBUG raw: dnszone_show(u'10.in-addr.arpa.', version=u'2.228') 2018-02-15T06:41:39Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:41:39Z DEBUG raw: dnszone_show(u'in-addr.arpa.', version=u'2.228') 2018-02-15T06:41:39Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:41:39Z DEBUG raw: dnszone_show(u'arpa.', version=u'2.228') 2018-02-15T06:41:39Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:41:39Z DEBUG raw: dnsrecord_add(u'pytest.test', u'replica3', arecord=u'1', version=u'2.228') 2018-02-15T06:41:39Z DEBUG dnsrecord_add(, , arecord=(u'1',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:41:39Z INFO Replica DNS records could not be added on master: invalid 'ip_address': invalid IP address format 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl is-active ntpd.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout=active 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl disable ntpd.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout= 2018-02-15T06:41:39Z DEBUG stderr=Removed symlink /etc/systemd/system/multi-user.target.wants/ntpd.service. 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:41:39Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl start ntpd.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout= 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl is-active ntpd.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout=active 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Destroyed connection context.ldap2_140100000171856 2018-02-15T06:41:39Z DEBUG Backing up system configuration file '/etc/ipa/default.conf' 2018-02-15T06:41:39Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=keyctl get_persistent @s 0 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout=668368777 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Enabling persistent keyring CCACHE 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl is-active krb5kdc.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=3 2018-02-15T06:41:39Z DEBUG stdout=unknown 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl stop krb5kdc.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout= 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Configuring Kerberos KDC (krb5kdc) 2018-02-15T06:41:39Z DEBUG [1/5]: configuring KDC 2018-02-15T06:41:39Z DEBUG Backing up system configuration file '/var/kerberos/krb5kdc/kdc.conf' 2018-02-15T06:41:39Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Backing up system configuration file '/etc/krb5.conf' 2018-02-15T06:41:39Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb5.ini' 2018-02-15T06:41:39Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb.con' 2018-02-15T06:41:39Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krbrealm.con' 2018-02-15T06:41:39Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=klist -V 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout=Kerberos 5 version 1.15.1 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Backing up system configuration file '/etc/sysconfig/krb5kdc' 2018-02-15T06:41:39Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout= 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/sbin/restorecon /etc/sysconfig/krb5kdc 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout= 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG duration: 0 seconds 2018-02-15T06:41:39Z DEBUG [2/5]: adding the password extension to the directory 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpOepNuz -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_pwd_extop add nsslapd-pluginpath: libipa_pwd_extop add nsslapd-plugininitfunc: ipapwd_init add nsslapd-plugintype: extendedop add nsslapd-pluginbetxn: on add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_pwd_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support saving passwords in multiple formats for different consumers (krb5, samba, freeradius, etc.) add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=pytest,dc=test adding new entry "cn=ipa_pwd_extop,cn=plugins,cn=config" modify complete 2018-02-15T06:41:39Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2018-02-15T06:41:39Z DEBUG duration: 0 seconds 2018-02-15T06:41:39Z DEBUG [3/5]: creating anonymous principal 2018-02-15T06:41:39Z DEBUG duration: 0 seconds 2018-02-15T06:41:39Z DEBUG [4/5]: starting the KDC 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl start krb5kdc.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout= 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl is-active krb5kdc.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout=active 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG duration: 0 seconds 2018-02-15T06:41:39Z DEBUG [5/5]: configuring KDC to start on boot 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl is-enabled krb5kdc.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=1 2018-02-15T06:41:39Z DEBUG stdout=disabled 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl disable krb5kdc.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout= 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG duration: 0 seconds 2018-02-15T06:41:39Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Configuring kadmin 2018-02-15T06:41:39Z DEBUG [1/2]: starting kadmin 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl is-active kadmin.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=3 2018-02-15T06:41:39Z DEBUG stdout=failed 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl restart kadmin.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout= 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl is-active kadmin.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout=active 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG duration: 0 seconds 2018-02-15T06:41:39Z DEBUG [2/2]: configuring kadmin to start on boot 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl is-enabled kadmin.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=1 2018-02-15T06:41:39Z DEBUG stdout=disabled 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/bin/systemctl disable kadmin.service 2018-02-15T06:41:39Z DEBUG Process finished, return code=0 2018-02-15T06:41:39Z DEBUG stdout= 2018-02-15T06:41:39Z DEBUG stderr= 2018-02-15T06:41:39Z DEBUG duration: 0 seconds 2018-02-15T06:41:39Z DEBUG Done configuring kadmin. 2018-02-15T06:41:39Z DEBUG Configuring directory server (dirsrv) 2018-02-15T06:41:39Z DEBUG [1/3]: configuring TLS for DS instance 2018-02-15T06:41:39Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:39Z DEBUG Starting external process 2018-02-15T06:41:39Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-PYTEST-TEST/ -L -n PYTEST.TEST IPA CA -a -f /etc/dirsrv/slapd-PYTEST-TEST/pwdfile.txt 2018-02-15T06:41:40Z DEBUG Process finished, return code=255 2018-02-15T06:41:40Z DEBUG stdout= Database needs user init 2018-02-15T06:41:40Z DEBUG stderr=certutil: Could not find cert: PYTEST.TEST IPA CA : PR_FILE_NOT_FOUND_ERROR: File not found 2018-02-15T06:41:40Z DEBUG Starting external process 2018-02-15T06:41:40Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-PYTEST-TEST/ -N -f /etc/dirsrv/slapd-PYTEST-TEST/pwdfile.txt -f /etc/dirsrv/slapd-PYTEST-TEST/pwdfile.txt 2018-02-15T06:41:40Z DEBUG Process finished, return code=0 2018-02-15T06:41:40Z DEBUG stdout= 2018-02-15T06:41:40Z DEBUG stderr= 2018-02-15T06:41:40Z DEBUG Starting external process 2018-02-15T06:41:40Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-PYTEST-TEST/ -A -n PYTEST.TEST IPA CA -t CT,C,C -a -f /etc/dirsrv/slapd-PYTEST-TEST/pwdfile.txt 2018-02-15T06:41:40Z DEBUG Process finished, return code=0 2018-02-15T06:41:40Z DEBUG stdout= 2018-02-15T06:41:40Z DEBUG stderr= 2018-02-15T06:41:40Z DEBUG certmonger request is in state dbus.String(u'NEWLY_ADDED_READING_KEYINFO', variant_level=1) 2018-02-15T06:41:45Z DEBUG certmonger request is in state dbus.String(u'POST_SAVED_CERT', variant_level=1) 2018-02-15T06:41:50Z DEBUG certmonger request is in state dbus.String(u'POST_SAVED_CERT', variant_level=1) 2018-02-15T06:41:55Z DEBUG certmonger request is in state dbus.String(u'MONITORING', variant_level=1) 2018-02-15T06:41:55Z DEBUG Destroyed connection context.ldap2_140100023575440 2018-02-15T06:41:55Z DEBUG Created connection context.ldap2_140100023575440 2018-02-15T06:41:55Z DEBUG Starting external process 2018-02-15T06:41:55Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-PYTEST-TEST/ -L -n Server-Cert -a -f /etc/dirsrv/slapd-PYTEST-TEST/pwdfile.txt 2018-02-15T06:41:55Z DEBUG Process finished, return code=0 2018-02-15T06:41:55Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIEszCCA5ugAwIBAgIBLjANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtQWVRF U1QuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE4MDIx NTA2NDE0MFoXDTIwMDIxNjA2NDE0MFowNTEUMBIGA1UECgwLUFlURVNULlRFU1Qx HTAbBgNVBAMMFHJlcGxpY2EzLnB5dGVzdC50ZXN0MIIBIjANBgkqhkiG9w0BAQEF AAOCAQ8AMIIBCgKCAQEA5jqJXJUF/r+3j91Eqoa86PnTAjyqGBcDkEblKLyfkhel bNmrx1TLhlqQky/sJQCsyh3I6oVV5bx+1VoZ0GpWSV/WkXAE3c3B3+zhBjp3x5bD cbMUXwzpOrtF0A3CsCb7mLxRP0c0eRtp1XUAYYBnosFyVbeUeC5k1LMjur55kyFr 2xJP+5WcZQr0SgIsZH6E81UnhaJPqLOfnAJ5fvOCW666YUYFq+EMiC5lY41unTMt KpnLUaXTFgpK6Ru0bZ3ZzHO1uFNBql+dVqj1Mj2Qp3mVJhEa3W/g+f9dxgwX2vJr T+RvO0FPdNH2ZQXy7jjodXtPpaqE4Nz4j1OqppBBRQIDAQABo4IByzCCAccwHwYD VR0jBBgwFoAUoHRTQ2vzwnNeeXejNg9YPJjEiUowPQYIKwYBBQUHAQEEMTAvMC0G CCsGAQUFBzABhiFodHRwOi8vaXBhLWNhLnB5dGVzdC50ZXN0L2NhL29jc3AwDgYD VR0PAQH/BAQDAgTwMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjB2BgNV HR8EbzBtMGugM6Axhi9odHRwOi8vaXBhLWNhLnB5dGVzdC50ZXN0L2lwYS9jcmwv TWFzdGVyQ1JMLmJpbqI0pDIwMDEOMAwGA1UECgwFaXBhY2ExHjAcBgNVBAMMFUNl cnRpZmljYXRlIEF1dGhvcml0eTAdBgNVHQ4EFgQUlX480LI7BHp3C1MBo7kKRnud a4MwgZ4GA1UdEQSBljCBk4IUcmVwbGljYTMucHl0ZXN0LnRlc3SgNQYKKwYBBAGC NxQCA6AnDCVsZGFwL3JlcGxpY2EzLnB5dGVzdC50ZXN0QFBZVEVTVC5URVNUoEQG BisGAQUCAqA6MDigDRsLUFlURVNULlRFU1ShJzAloAMCAQGhHjAcGwRsZGFwGxRy ZXBsaWNhMy5weXRlc3QudGVzdDANBgkqhkiG9w0BAQsFAAOCAQEAmX0cED2roTfn JNIf7agb/U5uDVF2mI0mQoGHqic8xriT7jKXEqSmDQHHDMWXAZquwuCST/Kf8sTb IRCnIVOUvKPtV8YKND7ZoKxJ67Z9vhJwPzYqxaAkRB7hsgSxNgFDwbeLHeYxq2su hYv1Bksr3cjoV8kzZ1H9nYafvLQDthG2V2H+cKDco94yP44KwXNRQprHy57xJxiw D3qBiJdIKiilmNxQA02Oyr2s/BByXABnorFK84Ccr1+MRfmxwHIpsfWXAv98ymwM 7bHZ2SxfzOh2atrExGjiZhF0Vlj1YgbI93sWvFsabbE2AZrm00rJIvXB1693E6SD 3SLL4pLg1g== -----END CERTIFICATE----- 2018-02-15T06:41:55Z DEBUG stderr= 2018-02-15T06:41:55Z DEBUG retrieving schema for SchemaCache url=ldap://replica3.pytest.test:389 conn= 2018-02-15T06:41:55Z DEBUG duration: 15 seconds 2018-02-15T06:41:55Z DEBUG [2/3]: importing CA certificates from LDAP 2018-02-15T06:41:55Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:41:55Z DEBUG Starting external process 2018-02-15T06:41:55Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-PYTEST-TEST/ -A -n PYTEST.TEST IPA CA -t CT,C,C -f /etc/dirsrv/slapd-PYTEST-TEST/pwdfile.txt 2018-02-15T06:41:55Z DEBUG Process finished, return code=0 2018-02-15T06:41:55Z DEBUG stdout= 2018-02-15T06:41:55Z DEBUG stderr= 2018-02-15T06:41:55Z DEBUG duration: 0 seconds 2018-02-15T06:41:55Z DEBUG [3/3]: restarting directory server 2018-02-15T06:41:55Z DEBUG Destroyed connection context.ldap2_140100023575440 2018-02-15T06:41:55Z DEBUG Starting external process 2018-02-15T06:41:55Z DEBUG args=/bin/systemctl --system daemon-reload 2018-02-15T06:41:55Z DEBUG Process finished, return code=0 2018-02-15T06:41:55Z DEBUG stdout= 2018-02-15T06:41:55Z DEBUG stderr= 2018-02-15T06:41:55Z DEBUG Starting external process 2018-02-15T06:41:55Z DEBUG args=/bin/systemctl restart dirsrv@PYTEST-TEST.service 2018-02-15T06:42:01Z DEBUG Process finished, return code=0 2018-02-15T06:42:01Z DEBUG stdout= 2018-02-15T06:42:01Z DEBUG stderr= 2018-02-15T06:42:01Z DEBUG Starting external process 2018-02-15T06:42:01Z DEBUG args=/bin/systemctl is-active dirsrv@PYTEST-TEST.service 2018-02-15T06:42:01Z DEBUG Process finished, return code=0 2018-02-15T06:42:01Z DEBUG stdout=active 2018-02-15T06:42:01Z DEBUG stderr= 2018-02-15T06:42:01Z DEBUG wait_for_open_ports: localhost [389] timeout 300 2018-02-15T06:42:01Z DEBUG waiting for port: 389 2018-02-15T06:42:01Z DEBUG SUCCESS: port: 389 2018-02-15T06:42:01Z DEBUG Starting external process 2018-02-15T06:42:01Z DEBUG args=/bin/systemctl is-active dirsrv@PYTEST-TEST.service 2018-02-15T06:42:01Z DEBUG Process finished, return code=0 2018-02-15T06:42:01Z DEBUG stdout=active 2018-02-15T06:42:01Z DEBUG stderr= 2018-02-15T06:42:01Z DEBUG Created connection context.ldap2_140100023575440 2018-02-15T06:42:01Z DEBUG duration: 5 seconds 2018-02-15T06:42:01Z DEBUG Done configuring directory server (dirsrv). 2018-02-15T06:42:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:01Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:01Z DEBUG Configuring the web interface (httpd) 2018-02-15T06:42:01Z DEBUG [1/22]: stopping httpd 2018-02-15T06:42:01Z DEBUG Starting external process 2018-02-15T06:42:01Z DEBUG args=/bin/systemctl is-active httpd.service 2018-02-15T06:42:01Z DEBUG Process finished, return code=3 2018-02-15T06:42:01Z DEBUG stdout=failed 2018-02-15T06:42:01Z DEBUG stderr= 2018-02-15T06:42:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:01Z DEBUG Starting external process 2018-02-15T06:42:01Z DEBUG args=/bin/systemctl stop httpd.service 2018-02-15T06:42:01Z DEBUG Process finished, return code=0 2018-02-15T06:42:01Z DEBUG stdout= 2018-02-15T06:42:01Z DEBUG stderr= 2018-02-15T06:42:01Z DEBUG duration: 0 seconds 2018-02-15T06:42:01Z DEBUG [2/22]: setting mod_nss port to 443 2018-02-15T06:42:01Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/nss.conf' 2018-02-15T06:42:01Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:01Z DEBUG duration: 0 seconds 2018-02-15T06:42:01Z DEBUG [3/22]: setting mod_nss cipher suite 2018-02-15T06:42:01Z DEBUG duration: 0 seconds 2018-02-15T06:42:01Z DEBUG [4/22]: setting mod_nss protocol list to TLSv1.0 - TLSv1.2 2018-02-15T06:42:01Z DEBUG duration: 0 seconds 2018-02-15T06:42:01Z DEBUG [5/22]: setting mod_nss password file 2018-02-15T06:42:01Z DEBUG duration: 0 seconds 2018-02-15T06:42:01Z DEBUG [6/22]: enabling mod_nss renegotiate 2018-02-15T06:42:01Z DEBUG duration: 0 seconds 2018-02-15T06:42:01Z DEBUG [7/22]: disabling mod_nss OCSP 2018-02-15T06:42:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:42:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:42:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:42:01Z DEBUG duration: 0 seconds 2018-02-15T06:42:01Z DEBUG [8/22]: adding URL rewriting rules 2018-02-15T06:42:01Z DEBUG duration: 0 seconds 2018-02-15T06:42:01Z DEBUG [9/22]: configuring httpd 2018-02-15T06:42:01Z DEBUG Starting external process 2018-02-15T06:42:01Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-15T06:42:01Z DEBUG Process finished, return code=0 2018-02-15T06:42:01Z DEBUG stdout= 2018-02-15T06:42:01Z DEBUG stderr= 2018-02-15T06:42:01Z DEBUG Starting external process 2018-02-15T06:42:01Z DEBUG args=/sbin/restorecon /etc/systemd/system/httpd.service.d/ipa.conf 2018-02-15T06:42:01Z DEBUG Process finished, return code=0 2018-02-15T06:42:01Z DEBUG stdout= 2018-02-15T06:42:01Z DEBUG stderr= 2018-02-15T06:42:01Z DEBUG Starting external process 2018-02-15T06:42:01Z DEBUG args=/bin/systemctl --system daemon-reload 2018-02-15T06:42:01Z DEBUG Process finished, return code=0 2018-02-15T06:42:01Z DEBUG stdout= 2018-02-15T06:42:01Z DEBUG stderr= 2018-02-15T06:42:01Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ipa.conf' 2018-02-15T06:42:01Z DEBUG -> Not backing up - '/etc/httpd/conf.d/ipa.conf' doesn't exist 2018-02-15T06:42:01Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ipa-rewrite.conf' 2018-02-15T06:42:01Z DEBUG -> Not backing up - '/etc/httpd/conf.d/ipa-rewrite.conf' doesn't exist 2018-02-15T06:42:01Z DEBUG duration: 0 seconds 2018-02-15T06:42:01Z DEBUG [10/22]: setting up httpd keytab 2018-02-15T06:42:01Z DEBUG raw: service_add(u'HTTP/replica3.pytest.test@PYTEST.TEST', force=True, version=u'2.228') 2018-02-15T06:42:01Z DEBUG service_add(ipapython.kerberos.Principal('HTTP/replica3.pytest.test@PYTEST.TEST'), force=True, all=False, raw=False, version=u'2.228', no_members=False) 2018-02-15T06:42:01Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket from SchemaCache 2018-02-15T06:42:01Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket conn= 2018-02-15T06:42:01Z DEBUG raw: host_show(u'replica3.pytest.test', version=u'2.228') 2018-02-15T06:42:01Z DEBUG host_show(u'replica3.pytest.test', rights=False, all=False, raw=False, version=u'2.228', no_members=False) 2018-02-15T06:42:01Z DEBUG Backing up system configuration file '/var/lib/ipa/gssproxy/http.keytab' 2018-02-15T06:42:01Z DEBUG -> Not backing up - '/var/lib/ipa/gssproxy/http.keytab' doesn't exist 2018-02-15T06:42:01Z DEBUG Starting external process 2018-02-15T06:42:01Z DEBUG args=/usr/sbin/ipa-getkeytab -k /var/lib/ipa/gssproxy/http.keytab -p HTTP/replica3.pytest.test@PYTEST.TEST -H ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket -Y EXTERNAL 2018-02-15T06:42:01Z DEBUG Process finished, return code=0 2018-02-15T06:42:01Z DEBUG stdout= 2018-02-15T06:42:01Z DEBUG stderr=Keytab successfully retrieved and stored in: /var/lib/ipa/gssproxy/http.keytab 2018-02-15T06:42:02Z DEBUG duration: 1 seconds 2018-02-15T06:42:02Z DEBUG [11/22]: configuring Gssproxy 2018-02-15T06:42:02Z DEBUG Starting external process 2018-02-15T06:42:02Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-15T06:42:02Z DEBUG Process finished, return code=0 2018-02-15T06:42:02Z DEBUG stdout= 2018-02-15T06:42:02Z DEBUG stderr= 2018-02-15T06:42:02Z DEBUG Starting external process 2018-02-15T06:42:02Z DEBUG args=/sbin/restorecon /etc/gssproxy/10-ipa.conf 2018-02-15T06:42:02Z DEBUG Process finished, return code=0 2018-02-15T06:42:02Z DEBUG stdout= 2018-02-15T06:42:02Z DEBUG stderr= 2018-02-15T06:42:02Z DEBUG Starting external process 2018-02-15T06:42:02Z DEBUG args=/bin/systemctl restart gssproxy.service 2018-02-15T06:42:02Z DEBUG Process finished, return code=0 2018-02-15T06:42:02Z DEBUG stdout= 2018-02-15T06:42:02Z DEBUG stderr= 2018-02-15T06:42:02Z DEBUG Starting external process 2018-02-15T06:42:02Z DEBUG args=/bin/systemctl is-active gssproxy.service 2018-02-15T06:42:02Z DEBUG Process finished, return code=0 2018-02-15T06:42:02Z DEBUG stdout=active 2018-02-15T06:42:02Z DEBUG stderr= 2018-02-15T06:42:02Z DEBUG duration: 0 seconds 2018-02-15T06:42:02Z DEBUG [12/22]: setting up ssl 2018-02-15T06:42:02Z DEBUG Starting external process 2018-02-15T06:42:02Z DEBUG args=/usr/bin/certutil -d /etc/httpd/alias -N -f /etc/httpd/alias/pwdfile.txt -f /etc/httpd/alias/pwdfile.txt 2018-02-15T06:42:03Z DEBUG Process finished, return code=0 2018-02-15T06:42:03Z DEBUG stdout= 2018-02-15T06:42:03Z DEBUG stderr= 2018-02-15T06:42:03Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:03Z DEBUG Starting external process 2018-02-15T06:42:03Z DEBUG args=/usr/bin/modutil -dbdir /etc/httpd/alias -force -list Root Certs 2018-02-15T06:42:03Z DEBUG Process finished, return code=0 2018-02-15T06:42:03Z DEBUG stdout= ----------------------------------------------------------- Name: Root Certs Library file: /etc/httpd/alias/libnssckbi.so Manufacturer: PKCS#11 Kit Description: PKCS#11 Kit Trust Module PKCS #11 Version 2.40 Library Version: 0.23 Cipher Enable Flags: None Default Mechanism Flags: None Slot: /etc/pki/ca-trust/source Slot Mechanism Flags: None Manufacturer: PKCS#11 Kit Type: Software Version Number: 0.23 Firmware Version: 0.0 Status: Enabled Token Name: System Trust Token Manufacturer: PKCS#11 Kit Token Model: p11-kit-trust Token Serial Number: 1 Token Version: 0.23 Token Firmware Version: 0.0 Access: NOT Write Protected Login Type: Public (no login required) User Pin: NOT Initialized Slot: /usr/share/pki/ca-trust-source Slot Mechanism Flags: None Manufacturer: PKCS#11 Kit Type: Software Version Number: 0.23 Firmware Version: 0.0 Status: Enabled Token Name: Default Trust Token Manufacturer: PKCS#11 Kit Token Model: p11-kit-trust Token Serial Number: 1 Token Version: 0.23 Token Firmware Version: 0.0 Access: NOT Write Protected Login Type: Public (no login required) User Pin: NOT Initialized ----------------------------------------------------------- 2018-02-15T06:42:03Z DEBUG stderr= 2018-02-15T06:42:03Z DEBUG Starting external process 2018-02-15T06:42:03Z DEBUG args=/usr/bin/modutil -dbdir /etc/httpd/alias -force -disable Root Certs 2018-02-15T06:42:03Z DEBUG Process finished, return code=0 2018-02-15T06:42:03Z DEBUG stdout=Slot "/etc/pki/ca-trust/source" disabled. Slot "/usr/share/pki/ca-trust-source" disabled. 2018-02-15T06:42:03Z DEBUG stderr= 2018-02-15T06:42:03Z DEBUG certmonger request is in state dbus.String(u'NEWLY_ADDED_READING_KEYINFO', variant_level=1) 2018-02-15T06:42:08Z DEBUG certmonger request is in state dbus.String(u'MONITORING', variant_level=1) 2018-02-15T06:42:08Z DEBUG Starting external process 2018-02-15T06:42:08Z DEBUG args=/usr/bin/certutil -d /etc/httpd/alias -L -n Server-Cert -a -f /etc/httpd/alias/pwdfile.txt 2018-02-15T06:42:08Z DEBUG Process finished, return code=0 2018-02-15T06:42:08Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIEszCCA5ugAwIBAgIBLzANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtQWVRF U1QuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE4MDIx NTA2NDIwNFoXDTIwMDIxNjA2NDIwNFowNTEUMBIGA1UECgwLUFlURVNULlRFU1Qx HTAbBgNVBAMMFHJlcGxpY2EzLnB5dGVzdC50ZXN0MIIBIjANBgkqhkiG9w0BAQEF AAOCAQ8AMIIBCgKCAQEAyuS3o1BjuSBK9SJolou8nKBUST3KsLVI4vpsgi8VALRx Vo0XVIEgPNinvQpJp5xpL20S03M9wyFqLO/y/ApSkctnyD5aBT4mnLyk7yKczRx/ pvOVzoFT+tlYLcQZmB6+fnk0o8MtUExZHGvTsSwWBG+U5/XEcS4OWiMDJZhg+buP YarhMB5pSLPKRBCNPCbGSaPe9tVOvbkgjVGxMkSiBVZr/sdqzZ6SM7XUX6sUJmkQ tWaOiiNmOpolqb12HnA9qjqqmNb28SH+WGm8jhv7Kq60q4czbJWfDVU2vw8nU6Mt poDlAC3OCfojX3tkjja1LYY0zPbSwfVgwan256opQwIDAQABo4IByzCCAccwHwYD VR0jBBgwFoAUoHRTQ2vzwnNeeXejNg9YPJjEiUowPQYIKwYBBQUHAQEEMTAvMC0G CCsGAQUFBzABhiFodHRwOi8vaXBhLWNhLnB5dGVzdC50ZXN0L2NhL29jc3AwDgYD VR0PAQH/BAQDAgTwMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjB2BgNV HR8EbzBtMGugM6Axhi9odHRwOi8vaXBhLWNhLnB5dGVzdC50ZXN0L2lwYS9jcmwv TWFzdGVyQ1JMLmJpbqI0pDIwMDEOMAwGA1UECgwFaXBhY2ExHjAcBgNVBAMMFUNl cnRpZmljYXRlIEF1dGhvcml0eTAdBgNVHQ4EFgQUCn8nYNpTtPfOXozpKSFAaLVu NWYwgZ4GA1UdEQSBljCBk4IUcmVwbGljYTMucHl0ZXN0LnRlc3SgNQYKKwYBBAGC NxQCA6AnDCVIVFRQL3JlcGxpY2EzLnB5dGVzdC50ZXN0QFBZVEVTVC5URVNUoEQG BisGAQUCAqA6MDigDRsLUFlURVNULlRFU1ShJzAloAMCAQGhHjAcGwRIVFRQGxRy ZXBsaWNhMy5weXRlc3QudGVzdDANBgkqhkiG9w0BAQsFAAOCAQEAOS04muW5VewQ WiKETng34rnuQxTIkK0OUwHNzQVdhDgT/UMnu+X7qNQBCpUPw6hNWVKBJ9rpNTur N6bCHGAgpX6EwEJ8bfQoTxysUtCcyju9wHc2UEy3KpPSl2iyK3MWbEVKVrnXkQp1 U8p8Jnw7kdBgGoAmsjEP88CjkwLb6CQeBsYyOD0QWmMuX1UcWIPBhAENiwQ4uWZa +W0/ug37WLgizTRgWrBpqANO2MYuUdoStWpir2r3DkMRn9L+ITaIKtjD2rxrhiCg BakmWZptOEe6saOn4sqtY0NXiWCVt+CYjCgDQQysFibwxeJ1aqguq17ZjpayIWek FTQF3+ZnpQ== -----END CERTIFICATE----- 2018-02-15T06:42:08Z DEBUG stderr= 2018-02-15T06:42:08Z DEBUG Starting external process 2018-02-15T06:42:08Z DEBUG args=/usr/bin/certutil -d /etc/httpd/alias -L -f /etc/httpd/alias/pwdfile.txt 2018-02-15T06:42:08Z DEBUG Process finished, return code=0 2018-02-15T06:42:08Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI Server-Cert u,u,u 2018-02-15T06:42:08Z DEBUG stderr= 2018-02-15T06:42:08Z DEBUG duration: 5 seconds 2018-02-15T06:42:08Z DEBUG [13/22]: configure certmonger for renewals 2018-02-15T06:42:08Z DEBUG Starting external process 2018-02-15T06:42:08Z DEBUG args=/bin/systemctl is-active certmonger.service 2018-02-15T06:42:08Z DEBUG Process finished, return code=0 2018-02-15T06:42:08Z DEBUG stdout=active 2018-02-15T06:42:08Z DEBUG stderr= 2018-02-15T06:42:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:08Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:08Z DEBUG duration: 0 seconds 2018-02-15T06:42:08Z DEBUG [14/22]: importing CA certificates from LDAP 2018-02-15T06:42:08Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:08Z DEBUG Starting external process 2018-02-15T06:42:08Z DEBUG args=/usr/bin/certutil -d /etc/httpd/alias -A -n PYTEST.TEST IPA CA -t CT,C,C -f /etc/httpd/alias/pwdfile.txt 2018-02-15T06:42:09Z DEBUG Process finished, return code=0 2018-02-15T06:42:09Z DEBUG stdout= 2018-02-15T06:42:09Z DEBUG stderr= 2018-02-15T06:42:09Z DEBUG duration: 0 seconds 2018-02-15T06:42:09Z DEBUG [15/22]: publish CA cert 2018-02-15T06:42:09Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:09Z DEBUG Starting external process 2018-02-15T06:42:09Z DEBUG args=/usr/bin/certutil -d /etc/httpd/alias -L -n PYTEST.TEST IPA CA -a -f /etc/httpd/alias/pwdfile.txt 2018-02-15T06:42:09Z DEBUG Process finished, return code=0 2018-02-15T06:42:09Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIDizCCAnOgAwIBAgIBATANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtQWVRF U1QuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE4MDIx NDA1NDM1NloXDTM4MDIxNDA1NDM1NlowNjEUMBIGA1UECgwLUFlURVNULlRFU1Qx HjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBALyHv9Rolz8gwuqBDIr9bUFbCteHNqZ+i2P6hVGE1wX4 dtG2kZrevk2T8+JO+8+4H3swPvXUUHypCNClIk8qJy95xM+4/PaQGd/V7NPftxVf 4DdA2VwnRtOayuJj73aOFqyqHwvdOn/bcaM6+/ANL0iyFz9UJDVit+WYpuZzgt7V loRILeNwXMXHL5PJzXIrYVSCG2F/8GBPZ21Ud+2cWSOiP+t/rjRVgglZZJ9RaNYo Rb475/KpaqU9o1pCz/+gTTQ+VT2SpJ2CkmMtEeTEEsYUolOZsu83FiQV7+4yaS4t T1CwyYTM6mUVzGSRzx/7j7a16G8SnUEy41zvFldN1F8CAwEAAaOBozCBoDAfBgNV HSMEGDAWgBSgdFNDa/PCc155d6M2D1g8mMSJSjAPBgNVHRMBAf8EBTADAQH/MA4G A1UdDwEB/wQEAwIBxjAdBgNVHQ4EFgQUoHRTQ2vzwnNeeXejNg9YPJjEiUowPQYI KwYBBQUHAQEEMTAvMC0GCCsGAQUFBzABhiFodHRwOi8vaXBhLWNhLnB5dGVzdC50 ZXN0L2NhL29jc3AwDQYJKoZIhvcNAQELBQADggEBAI6tiQWB5zPCQAlGwjUqeTbt +zOzPSvfwHQ9Joos1GzQKLq876RUVZTr4bqrZ9sKkkRGmkxnn+GU8uwXwsmjKqTo eer6Z7KMK4liPtBI9tM6G3w66b26PblUI3OC3sOU7eXpNfJrmgbVc5RghIxHnCO1 8uSjBVFhY1IMfUiANsWD8paRDh85wdKdJETZxsky/C2TRac4w6j9XsKuGbW8w+4Y LTkNEQNHncvaEDs/F39OiGaePxYVUzaZHZne3STWlb/i+fp+dfO8JCNyDwwnVCPh ma/UGrWNQ+YmrUbFPEX53y6bVV29vYi+yc/zB/QMTF+n7SskZde7afYhtTCmYVk= -----END CERTIFICATE----- 2018-02-15T06:42:09Z DEBUG stderr= 2018-02-15T06:42:09Z DEBUG duration: 0 seconds 2018-02-15T06:42:09Z DEBUG [16/22]: clean up any existing httpd ccaches 2018-02-15T06:42:09Z DEBUG duration: 0 seconds 2018-02-15T06:42:09Z DEBUG [17/22]: configuring SELinux for httpd 2018-02-15T06:42:09Z DEBUG Starting external process 2018-02-15T06:42:09Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-15T06:42:09Z DEBUG Process finished, return code=0 2018-02-15T06:42:09Z DEBUG stdout= 2018-02-15T06:42:09Z DEBUG stderr= 2018-02-15T06:42:09Z DEBUG Starting external process 2018-02-15T06:42:09Z DEBUG args=/usr/sbin/getsebool httpd_can_network_connect 2018-02-15T06:42:09Z DEBUG Process finished, return code=0 2018-02-15T06:42:09Z DEBUG stdout=httpd_can_network_connect --> on 2018-02-15T06:42:09Z DEBUG stderr= 2018-02-15T06:42:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:09Z DEBUG Starting external process 2018-02-15T06:42:09Z DEBUG args=/usr/sbin/getsebool httpd_dbus_sssd 2018-02-15T06:42:09Z DEBUG Process finished, return code=0 2018-02-15T06:42:09Z DEBUG stdout=httpd_dbus_sssd --> on 2018-02-15T06:42:09Z DEBUG stderr= 2018-02-15T06:42:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:09Z DEBUG Starting external process 2018-02-15T06:42:09Z DEBUG args=/usr/sbin/getsebool httpd_run_ipa 2018-02-15T06:42:09Z DEBUG Process finished, return code=0 2018-02-15T06:42:09Z DEBUG stdout=httpd_run_ipa --> on 2018-02-15T06:42:09Z DEBUG stderr= 2018-02-15T06:42:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:09Z DEBUG Starting external process 2018-02-15T06:42:09Z DEBUG args=/usr/sbin/getsebool httpd_manage_ipa 2018-02-15T06:42:09Z DEBUG Process finished, return code=0 2018-02-15T06:42:09Z DEBUG stdout=httpd_manage_ipa --> on 2018-02-15T06:42:09Z DEBUG stderr= 2018-02-15T06:42:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:09Z DEBUG duration: 0 seconds 2018-02-15T06:42:09Z DEBUG [18/22]: create KDC proxy config 2018-02-15T06:42:09Z DEBUG Backing up system configuration file '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' 2018-02-15T06:42:09Z DEBUG -> Not backing up - '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' doesn't exist 2018-02-15T06:42:09Z DEBUG duration: 0 seconds 2018-02-15T06:42:09Z DEBUG [19/22]: enable KDC proxy 2018-02-15T06:42:09Z DEBUG service KDC has all config values set 2018-02-15T06:42:09Z DEBUG duration: 0 seconds 2018-02-15T06:42:09Z DEBUG [20/22]: starting httpd 2018-02-15T06:42:09Z DEBUG Starting external process 2018-02-15T06:42:09Z DEBUG args=/bin/systemctl start httpd.service 2018-02-15T06:42:10Z DEBUG Process finished, return code=0 2018-02-15T06:42:10Z DEBUG stdout= 2018-02-15T06:42:10Z DEBUG stderr= 2018-02-15T06:42:10Z DEBUG Starting external process 2018-02-15T06:42:10Z DEBUG args=/bin/systemctl is-active httpd.service 2018-02-15T06:42:10Z DEBUG Process finished, return code=0 2018-02-15T06:42:10Z DEBUG stdout=active 2018-02-15T06:42:10Z DEBUG stderr= 2018-02-15T06:42:10Z DEBUG duration: 0 seconds 2018-02-15T06:42:10Z DEBUG [21/22]: configuring httpd to start on boot 2018-02-15T06:42:10Z DEBUG Starting external process 2018-02-15T06:42:10Z DEBUG args=/bin/systemctl is-enabled httpd.service 2018-02-15T06:42:10Z DEBUG Process finished, return code=1 2018-02-15T06:42:10Z DEBUG stdout=disabled 2018-02-15T06:42:10Z DEBUG stderr= 2018-02-15T06:42:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:10Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:10Z DEBUG Starting external process 2018-02-15T06:42:10Z DEBUG args=/bin/systemctl disable httpd.service 2018-02-15T06:42:11Z DEBUG Process finished, return code=0 2018-02-15T06:42:11Z DEBUG stdout= 2018-02-15T06:42:11Z DEBUG stderr= 2018-02-15T06:42:11Z DEBUG duration: 0 seconds 2018-02-15T06:42:11Z DEBUG [22/22]: enabling oddjobd 2018-02-15T06:42:11Z DEBUG Starting external process 2018-02-15T06:42:11Z DEBUG args=/bin/systemctl is-active oddjobd.service 2018-02-15T06:42:11Z DEBUG Process finished, return code=3 2018-02-15T06:42:11Z DEBUG stdout=unknown 2018-02-15T06:42:11Z DEBUG stderr= 2018-02-15T06:42:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:11Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:11Z DEBUG Starting external process 2018-02-15T06:42:11Z DEBUG args=/bin/systemctl is-enabled oddjobd.service 2018-02-15T06:42:11Z DEBUG Process finished, return code=1 2018-02-15T06:42:11Z DEBUG stdout=disabled 2018-02-15T06:42:11Z DEBUG stderr= 2018-02-15T06:42:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:11Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:11Z DEBUG Starting external process 2018-02-15T06:42:11Z DEBUG args=/bin/systemctl enable oddjobd.service 2018-02-15T06:42:11Z DEBUG Process finished, return code=0 2018-02-15T06:42:11Z DEBUG stdout= 2018-02-15T06:42:11Z DEBUG stderr=Created symlink from /etc/systemd/system/multi-user.target.wants/oddjobd.service to /usr/lib/systemd/system/oddjobd.service. 2018-02-15T06:42:11Z DEBUG Starting external process 2018-02-15T06:42:11Z DEBUG args=/bin/systemctl start oddjobd.service 2018-02-15T06:42:11Z DEBUG Process finished, return code=0 2018-02-15T06:42:11Z DEBUG stdout= 2018-02-15T06:42:11Z DEBUG stderr= 2018-02-15T06:42:11Z DEBUG Starting external process 2018-02-15T06:42:11Z DEBUG args=/bin/systemctl is-active oddjobd.service 2018-02-15T06:42:11Z DEBUG Process finished, return code=0 2018-02-15T06:42:11Z DEBUG stdout=active 2018-02-15T06:42:11Z DEBUG stderr= 2018-02-15T06:42:11Z DEBUG duration: 0 seconds 2018-02-15T06:42:11Z DEBUG Done configuring the web interface (httpd). 2018-02-15T06:42:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:11Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:11Z DEBUG Configuring ipa-otpd 2018-02-15T06:42:11Z DEBUG [1/2]: starting ipa-otpd 2018-02-15T06:42:11Z DEBUG Starting external process 2018-02-15T06:42:11Z DEBUG args=/bin/systemctl is-active ipa-otpd.socket 2018-02-15T06:42:11Z DEBUG Process finished, return code=3 2018-02-15T06:42:11Z DEBUG stdout=unknown 2018-02-15T06:42:11Z DEBUG stderr= 2018-02-15T06:42:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:11Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:11Z DEBUG Starting external process 2018-02-15T06:42:11Z DEBUG args=/bin/systemctl restart ipa-otpd.socket 2018-02-15T06:42:12Z DEBUG Process finished, return code=0 2018-02-15T06:42:12Z DEBUG stdout= 2018-02-15T06:42:12Z DEBUG stderr= 2018-02-15T06:42:12Z DEBUG Starting external process 2018-02-15T06:42:12Z DEBUG args=/bin/systemctl is-active ipa-otpd.socket 2018-02-15T06:42:12Z DEBUG Process finished, return code=0 2018-02-15T06:42:12Z DEBUG stdout=active 2018-02-15T06:42:12Z DEBUG stderr= 2018-02-15T06:42:12Z DEBUG duration: 0 seconds 2018-02-15T06:42:12Z DEBUG [2/2]: configuring ipa-otpd to start on boot 2018-02-15T06:42:12Z DEBUG Starting external process 2018-02-15T06:42:12Z DEBUG args=/bin/systemctl is-enabled ipa-otpd.socket 2018-02-15T06:42:12Z DEBUG Process finished, return code=1 2018-02-15T06:42:12Z DEBUG stdout=disabled 2018-02-15T06:42:12Z DEBUG stderr= 2018-02-15T06:42:12Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:12Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:12Z DEBUG Starting external process 2018-02-15T06:42:12Z DEBUG args=/bin/systemctl disable ipa-otpd.socket 2018-02-15T06:42:12Z DEBUG Process finished, return code=0 2018-02-15T06:42:12Z DEBUG stdout= 2018-02-15T06:42:12Z DEBUG stderr= 2018-02-15T06:42:12Z DEBUG duration: 0 seconds 2018-02-15T06:42:12Z DEBUG Done configuring ipa-otpd. 2018-02-15T06:42:12Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:12Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:12Z DEBUG Configuring ipa-custodia 2018-02-15T06:42:12Z DEBUG [1/4]: Generating ipa-custodia config file 2018-02-15T06:42:12Z DEBUG duration: 0 seconds 2018-02-15T06:42:12Z DEBUG [2/4]: Generating ipa-custodia keys 2018-02-15T06:42:13Z DEBUG duration: 0 seconds 2018-02-15T06:42:13Z DEBUG [3/4]: starting ipa-custodia 2018-02-15T06:42:13Z DEBUG Starting external process 2018-02-15T06:42:13Z DEBUG args=/bin/systemctl is-active ipa-custodia.service 2018-02-15T06:42:13Z DEBUG Process finished, return code=3 2018-02-15T06:42:13Z DEBUG stdout=unknown 2018-02-15T06:42:13Z DEBUG stderr= 2018-02-15T06:42:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:13Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:13Z DEBUG Starting external process 2018-02-15T06:42:13Z DEBUG args=/bin/systemctl restart ipa-custodia.service 2018-02-15T06:42:13Z DEBUG Process finished, return code=0 2018-02-15T06:42:13Z DEBUG stdout= 2018-02-15T06:42:13Z DEBUG stderr= 2018-02-15T06:42:13Z DEBUG Starting external process 2018-02-15T06:42:13Z DEBUG args=/bin/systemctl is-active ipa-custodia.service 2018-02-15T06:42:13Z DEBUG Process finished, return code=0 2018-02-15T06:42:13Z DEBUG stdout=active 2018-02-15T06:42:13Z DEBUG stderr= 2018-02-15T06:42:13Z DEBUG duration: 0 seconds 2018-02-15T06:42:13Z DEBUG [4/4]: configuring ipa-custodia to start on boot 2018-02-15T06:42:13Z DEBUG Starting external process 2018-02-15T06:42:13Z DEBUG args=/bin/systemctl is-enabled ipa-custodia.service 2018-02-15T06:42:13Z DEBUG Process finished, return code=1 2018-02-15T06:42:13Z DEBUG stdout=disabled 2018-02-15T06:42:13Z DEBUG stderr= 2018-02-15T06:42:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:13Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:13Z DEBUG Starting external process 2018-02-15T06:42:13Z DEBUG args=/bin/systemctl disable ipa-custodia.service 2018-02-15T06:42:13Z DEBUG Process finished, return code=0 2018-02-15T06:42:13Z DEBUG stdout= 2018-02-15T06:42:13Z DEBUG stderr= 2018-02-15T06:42:13Z DEBUG duration: 0 seconds 2018-02-15T06:42:13Z DEBUG Done configuring ipa-custodia. 2018-02-15T06:42:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:13Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:13Z INFO Waiting up to 300 seconds to see our keys appear on host: master.pytest.test 2018-02-15T06:42:14Z DEBUG Starting external process 2018-02-15T06:42:14Z DEBUG args=/usr/bin/certutil -d /tmp/tmp6GDpCf -N -f /tmp/tmp6GDpCf/pwdfile.txt -f /tmp/tmp6GDpCf/pwdfile.txt 2018-02-15T06:42:14Z DEBUG Process finished, return code=0 2018-02-15T06:42:14Z DEBUG stdout= 2018-02-15T06:42:14Z DEBUG stderr= 2018-02-15T06:42:17Z DEBUG Starting external process 2018-02-15T06:42:17Z DEBUG args=/usr/bin/pk12util -d /tmp/tmp6GDpCf -k /tmp/tmp6GDpCf/pwdfile.txt -n caSigningCert cert-pki-ca -i /tmp/tmp6GDpCf/pk12file -w /tmp/tmp6GDpCf/pk12pwfile 2018-02-15T06:42:20Z DEBUG Process finished, return code=0 2018-02-15T06:42:20Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL 2018-02-15T06:42:20Z DEBUG stderr= 2018-02-15T06:42:23Z DEBUG Starting external process 2018-02-15T06:42:23Z DEBUG args=/usr/bin/pk12util -d /tmp/tmp6GDpCf -k /tmp/tmp6GDpCf/pwdfile.txt -n ocspSigningCert cert-pki-ca -i /tmp/tmp6GDpCf/pk12file -w /tmp/tmp6GDpCf/pk12pwfile 2018-02-15T06:42:25Z DEBUG Process finished, return code=0 2018-02-15T06:42:25Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL 2018-02-15T06:42:25Z DEBUG stderr= 2018-02-15T06:42:29Z DEBUG Starting external process 2018-02-15T06:42:29Z DEBUG args=/usr/bin/pk12util -d /tmp/tmp6GDpCf -k /tmp/tmp6GDpCf/pwdfile.txt -n auditSigningCert cert-pki-ca -i /tmp/tmp6GDpCf/pk12file -w /tmp/tmp6GDpCf/pk12pwfile 2018-02-15T06:42:31Z DEBUG Process finished, return code=0 2018-02-15T06:42:31Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL 2018-02-15T06:42:31Z DEBUG stderr= 2018-02-15T06:42:35Z DEBUG Starting external process 2018-02-15T06:42:35Z DEBUG args=/usr/bin/pk12util -d /tmp/tmp6GDpCf -k /tmp/tmp6GDpCf/pwdfile.txt -n subsystemCert cert-pki-ca -i /tmp/tmp6GDpCf/pk12file -w /tmp/tmp6GDpCf/pk12pwfile 2018-02-15T06:42:38Z DEBUG Process finished, return code=0 2018-02-15T06:42:38Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL 2018-02-15T06:42:38Z DEBUG stderr= 2018-02-15T06:42:38Z DEBUG Starting external process 2018-02-15T06:42:38Z DEBUG args=/usr/bin/certutil -d /tmp/tmp6GDpCf -A -n PYTEST.TEST IPA CA -t CT,C,C -f /tmp/tmp6GDpCf/pwdfile.txt 2018-02-15T06:42:38Z DEBUG Process finished, return code=0 2018-02-15T06:42:38Z DEBUG stdout= 2018-02-15T06:42:38Z DEBUG stderr= 2018-02-15T06:42:38Z DEBUG Starting external process 2018-02-15T06:42:38Z DEBUG args=/usr/bin/PKCS12Export -d /tmp/tmp6GDpCf -p /tmp/tmp6GDpCf/pwdfile.txt -w /tmp/tmp6GDpCf/crtpwfile -o /tmp/tmpbYXXXFipa/cacert.p12 2018-02-15T06:42:38Z DEBUG Process finished, return code=0 2018-02-15T06:42:38Z DEBUG stdout=Export complete. 2018-02-15T06:42:38Z DEBUG stderr= 2018-02-15T06:42:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:42:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:42:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:38Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:38Z DEBUG Configuring certificate server (pki-tomcatd) 2018-02-15T06:42:38Z DEBUG [1/2]: configure certmonger for renewals 2018-02-15T06:42:38Z DEBUG Starting external process 2018-02-15T06:42:38Z DEBUG args=/bin/systemctl enable certmonger.service 2018-02-15T06:42:38Z DEBUG Process finished, return code=0 2018-02-15T06:42:38Z DEBUG stdout= 2018-02-15T06:42:38Z DEBUG stderr= 2018-02-15T06:42:38Z DEBUG Starting external process 2018-02-15T06:42:38Z DEBUG args=/bin/systemctl start messagebus.service 2018-02-15T06:42:38Z DEBUG Process finished, return code=0 2018-02-15T06:42:38Z DEBUG stdout= 2018-02-15T06:42:38Z DEBUG stderr= 2018-02-15T06:42:38Z DEBUG Starting external process 2018-02-15T06:42:38Z DEBUG args=/bin/systemctl is-active messagebus.service 2018-02-15T06:42:38Z DEBUG Process finished, return code=0 2018-02-15T06:42:38Z DEBUG stdout=active 2018-02-15T06:42:38Z DEBUG stderr= 2018-02-15T06:42:38Z DEBUG Starting external process 2018-02-15T06:42:38Z DEBUG args=/bin/systemctl start certmonger.service 2018-02-15T06:42:38Z DEBUG Process finished, return code=0 2018-02-15T06:42:38Z DEBUG stdout= 2018-02-15T06:42:38Z DEBUG stderr= 2018-02-15T06:42:38Z DEBUG Starting external process 2018-02-15T06:42:38Z DEBUG args=/bin/systemctl is-active certmonger.service 2018-02-15T06:42:38Z DEBUG Process finished, return code=0 2018-02-15T06:42:38Z DEBUG stdout=active 2018-02-15T06:42:38Z DEBUG stderr= 2018-02-15T06:42:39Z DEBUG duration: 0 seconds 2018-02-15T06:42:39Z DEBUG [2/2]: Importing RA key 2018-02-15T06:42:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:39Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:39Z INFO Waiting up to 300 seconds to see our keys appear on host: master.pytest.test 2018-02-15T06:42:39Z DEBUG Starting external process 2018-02-15T06:42:39Z DEBUG args=/usr/bin/openssl pkcs12 -in /tmp/tmpeSMkDV -clcerts -nokeys -out /var/lib/ipa/ra-agent.pem -passin pass:XXXXXXXX 2018-02-15T06:42:40Z DEBUG Process finished, return code=0 2018-02-15T06:42:40Z DEBUG stdout= 2018-02-15T06:42:40Z DEBUG stderr=MAC verified OK 2018-02-15T06:42:40Z DEBUG Starting external process 2018-02-15T06:42:40Z DEBUG args=/usr/bin/openssl pkcs12 -in /tmp/tmpeSMkDV -nocerts -nodes -out /var/lib/ipa/ra-agent.key -passin pass:XXXXXXXX 2018-02-15T06:42:40Z DEBUG Process finished, return code=0 2018-02-15T06:42:40Z DEBUG stdout= 2018-02-15T06:42:40Z DEBUG stderr=MAC verified OK 2018-02-15T06:42:40Z DEBUG Starting external process 2018-02-15T06:42:40Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-15T06:42:40Z DEBUG Process finished, return code=0 2018-02-15T06:42:40Z DEBUG stdout= 2018-02-15T06:42:40Z DEBUG stderr= 2018-02-15T06:42:40Z DEBUG Starting external process 2018-02-15T06:42:40Z DEBUG args=/sbin/restorecon /var/lib/ipa/ra-agent.pem 2018-02-15T06:42:40Z DEBUG Process finished, return code=0 2018-02-15T06:42:40Z DEBUG stdout= 2018-02-15T06:42:40Z DEBUG stderr= 2018-02-15T06:42:40Z DEBUG Starting external process 2018-02-15T06:42:40Z DEBUG args=/usr/sbin/selinuxenabled 2018-02-15T06:42:40Z DEBUG Process finished, return code=0 2018-02-15T06:42:40Z DEBUG stdout= 2018-02-15T06:42:40Z DEBUG stderr= 2018-02-15T06:42:40Z DEBUG Starting external process 2018-02-15T06:42:40Z DEBUG args=/sbin/restorecon /var/lib/ipa/ra-agent.key 2018-02-15T06:42:40Z DEBUG Process finished, return code=0 2018-02-15T06:42:40Z DEBUG stdout= 2018-02-15T06:42:40Z DEBUG stderr= 2018-02-15T06:42:41Z DEBUG duration: 1 seconds 2018-02-15T06:42:41Z DEBUG Done configuring certificate server (pki-tomcatd). 2018-02-15T06:42:41Z DEBUG retrieving schema for SchemaCache url=ldap://master.pytest.test conn= 2018-02-15T06:42:42Z DEBUG Configuring Kerberos KDC (krb5kdc) 2018-02-15T06:42:42Z DEBUG [1/1]: installing X509 Certificate for PKINIT 2018-02-15T06:42:42Z DEBUG certmonger request is in state dbus.String(u'NEWLY_ADDED_READING_KEYINFO', variant_level=1) 2018-02-15T06:42:47Z DEBUG certmonger request is in state dbus.String(u'SUBMITTING', variant_level=1) 2018-02-15T06:42:52Z DEBUG certmonger request is in state dbus.String(u'POST_SAVED_CERT', variant_level=1) 2018-02-15T06:42:58Z DEBUG certmonger request is in state dbus.String(u'MONITORING', variant_level=1) 2018-02-15T06:42:58Z DEBUG service KDC has all config values set 2018-02-15T06:42:58Z DEBUG duration: 15 seconds 2018-02-15T06:42:58Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2018-02-15T06:42:58Z DEBUG Starting external process 2018-02-15T06:42:58Z DEBUG args=/bin/systemctl restart krb5kdc.service 2018-02-15T06:42:58Z DEBUG Process finished, return code=0 2018-02-15T06:42:58Z DEBUG stdout= 2018-02-15T06:42:58Z DEBUG stderr= 2018-02-15T06:42:58Z DEBUG Starting external process 2018-02-15T06:42:58Z DEBUG args=/bin/systemctl is-active krb5kdc.service 2018-02-15T06:42:58Z DEBUG Process finished, return code=0 2018-02-15T06:42:58Z DEBUG stdout=active 2018-02-15T06:42:58Z DEBUG stderr= 2018-02-15T06:42:58Z DEBUG Applying LDAP updates 2018-02-15T06:42:58Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:42:58Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:42:58Z DEBUG Starting external process 2018-02-15T06:42:58Z DEBUG args=/bin/systemctl is-active dirsrv@PYTEST-TEST.service 2018-02-15T06:42:58Z DEBUG Process finished, return code=0 2018-02-15T06:42:58Z DEBUG stdout=active 2018-02-15T06:42:58Z DEBUG stderr= 2018-02-15T06:42:58Z DEBUG Upgrading IPA:. Estimated time: 1 minute 30 seconds 2018-02-15T06:42:58Z DEBUG [1/9]: stopping directory server 2018-02-15T06:42:58Z DEBUG Destroyed connection context.ldap2_140100023575440 2018-02-15T06:42:58Z DEBUG Starting external process 2018-02-15T06:42:58Z DEBUG args=/bin/systemctl stop dirsrv@PYTEST-TEST.service 2018-02-15T06:43:01Z DEBUG Process finished, return code=0 2018-02-15T06:43:01Z DEBUG stdout= 2018-02-15T06:43:01Z DEBUG stderr= 2018-02-15T06:43:01Z DEBUG duration: 2 seconds 2018-02-15T06:43:01Z DEBUG [2/9]: saving configuration 2018-02-15T06:43:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:43:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:43:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:43:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:43:01Z DEBUG duration: 0 seconds 2018-02-15T06:43:01Z DEBUG [3/9]: disabling listeners 2018-02-15T06:43:01Z DEBUG duration: 0 seconds 2018-02-15T06:43:01Z DEBUG [4/9]: enabling DS global lock 2018-02-15T06:43:01Z DEBUG duration: 0 seconds 2018-02-15T06:43:01Z DEBUG [5/9]: starting directory server 2018-02-15T06:43:01Z DEBUG Starting external process 2018-02-15T06:43:01Z DEBUG args=/bin/systemctl start dirsrv@PYTEST-TEST.service 2018-02-15T06:43:06Z DEBUG Process finished, return code=0 2018-02-15T06:43:06Z DEBUG stdout= 2018-02-15T06:43:06Z DEBUG stderr= 2018-02-15T06:43:06Z DEBUG Created connection context.ldap2_140100023575440 2018-02-15T06:43:06Z DEBUG duration: 5 seconds 2018-02-15T06:43:06Z DEBUG [6/9]: upgrading server 2018-02-15T06:43:06Z DEBUG importing all plugin modules in ipaserver.plugins... 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.aci 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.automember 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.automount 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.baseldap 2018-02-15T06:43:06Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.baseuser 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.batch 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.ca 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.caacl 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.cert 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.certmap 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.certprofile 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.config 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.delegation 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.dns 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.dogtag 2018-02-15T06:43:06Z DEBUG skipping plugin module ipaserver.plugins.dogtag: dogtag not selected as RA plugin 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.group 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.hbac 2018-02-15T06:43:06Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.hbactest 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.host 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.idrange 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.idviews 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.internal 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.join 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.ldap2 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.location 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.migration 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.misc 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.netgroup 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.otp 2018-02-15T06:43:06Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.otptoken 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.passwd 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.permission 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.ping 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.pkinit 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.privilege 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.rabase 2018-02-15T06:43:06Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.role 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.schema 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.selfservice 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.server 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.serverrole 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.serverroles 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.service 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.session 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.stageuser 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.sudo 2018-02-15T06:43:06Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.sudorule 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.topology 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.trust 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.user 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.vault 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.virtual 2018-02-15T06:43:06Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.whoami 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2018-02-15T06:43:06Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.dns 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2018-02-15T06:43:06Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2018-02-15T06:43:07Z DEBUG Created connection context.ldap2_140099962487952 2018-02-15T06:43:07Z DEBUG Destroyed connection context.ldap2_140099962487952 2018-02-15T06:43:07Z DEBUG Created connection context.ldap2_140099962487952 2018-02-15T06:43:07Z DEBUG Parsing update file '/usr/share/ipa/updates/05-pre_upgrade_plugins.update' 2018-02-15T06:43:07Z DEBUG Executing upgrade plugin: update_managed_post_first 2018-02-15T06:43:07Z DEBUG raw: update_managed_post_first 2018-02-15T06:43:07Z DEBUG Executing upgrade plugin: update_replica_attribute_lists 2018-02-15T06:43:07Z DEBUG raw: update_replica_attribute_lists 2018-02-15T06:43:07Z DEBUG Start replication agreement exclude list update task 2018-02-15T06:43:07Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket from SchemaCache 2018-02-15T06:43:07Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket conn= 2018-02-15T06:43:08Z DEBUG Found 1 agreement(s) 2018-02-15T06:43:08Z DEBUG me to master.pytest.test 2018-02-15T06:43:08Z DEBUG nsDS5ReplicatedAttributeList: No update necessary 2018-02-15T06:43:08Z DEBUG nsDS5ReplicatedAttributeListTotal: No update necessary 2018-02-15T06:43:08Z DEBUG nsds5ReplicaStripAttrs: No update necessary 2018-02-15T06:43:08Z DEBUG Done updating agreements 2018-02-15T06:43:08Z DEBUG Executing upgrade plugin: update_passync_privilege_check 2018-02-15T06:43:08Z DEBUG raw: update_passync_privilege_check 2018-02-15T06:43:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:43:08Z DEBUG Check if there is existing PassSync privilege 2018-02-15T06:43:08Z DEBUG PassSync privilege found, skip updating PassSync 2018-02-15T06:43:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:43:08Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:43:08Z DEBUG Executing upgrade plugin: update_referint 2018-02-15T06:43:08Z DEBUG raw: update_referint 2018-02-15T06:43:08Z DEBUG Upgrading referential integrity plugin configuration 2018-02-15T06:43:08Z DEBUG Initial value: LDAPEntry(ipapython.dn.DN('cn=referential integrity postoperation,cn=plugins,cn=config'), {u'nsslapd-pluginPath': ['libreferint-plugin'], u'cn': ['referential integrity postoperation'], u'referint-update-delay': ['0'], u'nsslapd-pluginVersion': ['1.3.7.5'], u'nsslapd-pluginDescription': ['referential integrity plugin'], u'nsslapd-pluginEnabled': ['on'], u'nsslapd-pluginId': ['referint'], u'objectClass': ['top', 'nsSlapdPlugin', 'extensibleObject'], u'nsslapd-plugin-depends-on-type': ['database'], u'nsslapd-pluginVendor': ['389 Project'], u'nsslapd-pluginprecedence': ['40'], u'referint-membership-attr': ['member', 'uniquemember', 'owner', 'seeAlso'], u'nsslapd-pluginType': ['betxnpostoperation'], u'referint-logfile': ['/var/log/dirsrv/slapd-PYTEST-TEST/referint'], u'nsslapd-pluginInitfunc': ['referint_postop_init']}) 2018-02-15T06:43:08Z DEBUG Plugin already uses new style, skipping 2018-02-15T06:43:08Z DEBUG Executing upgrade plugin: update_uniqueness_plugins_to_new_syntax 2018-02-15T06:43:08Z DEBUG raw: update_uniqueness_plugins_to_new_syntax 2018-02-15T06:43:08Z DEBUG No uniqueness plugin entries with old style configuration found 2018-02-15T06:43:08Z DEBUG Parsing update file '/usr/share/ipa/updates/10-config.update' 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG only: set nsslapd-ssl-check-hostname to 'on', current value [u'on'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Kerberos Principal Name 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG ipamodrdntargetattr: 2018-02-15T06:43:08Z DEBUG krbPrincipalName 2018-02-15T06:43:08Z DEBUG ipamodrdnsuffix: 2018-02-15T06:43:08Z DEBUG @PYTEST.TEST 2018-02-15T06:43:08Z DEBUG ipamodrdnsourceattr: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG ipamodrdnfilter: 2018-02-15T06:43:08Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2018-02-15T06:43:08Z DEBUG ipamodrdnscope: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG remove: '60' from nsslapd-pluginPrecedence, current value [] 2018-02-15T06:43:08Z DEBUG remove: '60' not in nsslapd-pluginPrecedence 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Kerberos Principal Name 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG ipamodrdntargetattr: 2018-02-15T06:43:08Z DEBUG krbPrincipalName 2018-02-15T06:43:08Z DEBUG ipamodrdnsuffix: 2018-02-15T06:43:08Z DEBUG @PYTEST.TEST 2018-02-15T06:43:08Z DEBUG ipamodrdnsourceattr: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG ipamodrdnfilter: 2018-02-15T06:43:08Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2018-02-15T06:43:08Z DEBUG ipamodrdnscope: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG IPA MODRDN 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG IPA MODRDN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG IPA MODRDN plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_modrdn 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Red Hat, Inc. 2018-02-15T06:43:08Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipamodrdn_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [u'60'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'60'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG IPA MODRDN 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG IPA MODRDN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG IPA MODRDN plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_modrdn 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Red Hat, Inc. 2018-02-15T06:43:08Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipamodrdn_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-directory: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/db 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG nsslapd-db-transaction-batch-val: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-lookthroughlimit: 2018-02-15T06:43:08Z DEBUG 5000 2018-02-15T06:43:08Z DEBUG nsslapd-db-deadlock-policy: 2018-02-15T06:43:08Z DEBUG 9 2018-02-15T06:43:08Z DEBUG nsslapd-db-transaction-batch-min-wait: 2018-02-15T06:43:08Z DEBUG 50 2018-02-15T06:43:08Z DEBUG nsslapd-db-locks: 2018-02-15T06:43:08Z DEBUG 50000 2018-02-15T06:43:08Z DEBUG nsslapd-serial-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-subtree-rename-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-backend-opt-level: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-db-logdirectory: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/db 2018-02-15T06:43:08Z DEBUG nsslapd-exclude-from-export: 2018-02-15T06:43:08Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2018-02-15T06:43:08Z DEBUG nsslapd-cache-autosize: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-db-transaction-batch-max-wait: 2018-02-15T06:43:08Z DEBUG 50 2018-02-15T06:43:08Z DEBUG nsslapd-rangelookthroughlimit: 2018-02-15T06:43:08Z DEBUG 5000 2018-02-15T06:43:08Z DEBUG nsslapd-dbcachesize: 2018-02-15T06:43:08Z DEBUG 164041113 2018-02-15T06:43:08Z DEBUG nsslapd-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-db-logbuf-size: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-import-cache-autosize: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-search-use-vlv-index: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pagedidlistscanlimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idlistscanlimit: 2018-02-15T06:43:08Z DEBUG 4000 2018-02-15T06:43:08Z DEBUG nsslapd-search-bypass-filter-test: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-db-compactdb-interval: 2018-02-15T06:43:08Z DEBUG 2592000 2018-02-15T06:43:08Z DEBUG nsslapd-pagedlookthroughlimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idl-switch: 2018-02-15T06:43:08Z DEBUG new 2018-02-15T06:43:08Z DEBUG nsslapd-db-durable-transaction: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-cache-autosize-split: 2018-02-15T06:43:08Z DEBUG 25 2018-02-15T06:43:08Z DEBUG nsslapd-db-private-import-mem: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-db-transaction-wait: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-db-checkpoint-interval: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-import-cachesize: 2018-02-15T06:43:08Z DEBUG 16777216 2018-02-15T06:43:08Z DEBUG replace: updated value [u'100000'] 2018-02-15T06:43:08Z DEBUG replace: updated value [u'100000'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-directory: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/db 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG nsslapd-db-transaction-batch-val: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-lookthroughlimit: 2018-02-15T06:43:08Z DEBUG 100000 2018-02-15T06:43:08Z DEBUG nsslapd-db-deadlock-policy: 2018-02-15T06:43:08Z DEBUG 9 2018-02-15T06:43:08Z DEBUG nsslapd-db-transaction-batch-min-wait: 2018-02-15T06:43:08Z DEBUG 50 2018-02-15T06:43:08Z DEBUG nsslapd-db-locks: 2018-02-15T06:43:08Z DEBUG 50000 2018-02-15T06:43:08Z DEBUG nsslapd-serial-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-subtree-rename-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-backend-opt-level: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-db-logdirectory: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/db 2018-02-15T06:43:08Z DEBUG nsslapd-exclude-from-export: 2018-02-15T06:43:08Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2018-02-15T06:43:08Z DEBUG nsslapd-cache-autosize: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-db-transaction-batch-max-wait: 2018-02-15T06:43:08Z DEBUG 50 2018-02-15T06:43:08Z DEBUG nsslapd-rangelookthroughlimit: 2018-02-15T06:43:08Z DEBUG 5000 2018-02-15T06:43:08Z DEBUG nsslapd-dbcachesize: 2018-02-15T06:43:08Z DEBUG 164041113 2018-02-15T06:43:08Z DEBUG nsslapd-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-db-logbuf-size: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-import-cache-autosize: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-search-use-vlv-index: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pagedidlistscanlimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idlistscanlimit: 2018-02-15T06:43:08Z DEBUG 100000 2018-02-15T06:43:08Z DEBUG nsslapd-search-bypass-filter-test: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-db-compactdb-interval: 2018-02-15T06:43:08Z DEBUG 2592000 2018-02-15T06:43:08Z DEBUG nsslapd-pagedlookthroughlimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idl-switch: 2018-02-15T06:43:08Z DEBUG new 2018-02-15T06:43:08Z DEBUG nsslapd-db-durable-transaction: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-cache-autosize-split: 2018-02-15T06:43:08Z DEBUG 25 2018-02-15T06:43:08Z DEBUG nsslapd-db-private-import-mem: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-db-transaction-wait: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-db-checkpoint-interval: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-import-cachesize: 2018-02-15T06:43:08Z DEBUG 16777216 2018-02-15T06:43:08Z DEBUG [(2, u'nsslapd-lookthroughlimit', [u'100000']), (2, u'nsslapd-idlistscanlimit', [u'100000'])] 2018-02-15T06:43:08Z DEBUG Updated 1 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG anonymous-limits 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG anonymous-limits 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG only: set nsslapd-anonlimitsdn to 'cn=anonymous-limits,cn=etc,dc=pytest,dc=test', current value [u''] 2018-02-15T06:43:08Z DEBUG only: updated value [u'cn=anonymous-limits,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG [(2, u'nsslapd-anonlimitsdn', [u'cn=anonymous-limits,cn=etc,dc=pytest,dc=test'])] 2018-02-15T06:43:08Z DEBUG Updated 1 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG add: 'dc=pytest,dc=test' to nsslapd-defaultNamingContext, current value [u'dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG only: set nsslapd-minssf-exclude-rootdse to 'on', current value [u'off'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG [(2, u'nsslapd-minssf-exclude-rootdse', [u'on'])] 2018-02-15T06:43:08Z DEBUG Updated 1 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ipa-winsync 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG ipawinsynchomedirattr: 2018-02-15T06:43:08Z DEBUG ipaHomesRootDir 2018-02-15T06:43:08Z DEBUG ipawinsyncnewuserocattr: 2018-02-15T06:43:08Z DEBUG ipauserobjectclasses 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_winsync 2018-02-15T06:43:08Z DEBUG ipawinsyncuserflatten: 2018-02-15T06:43:08Z DEBUG true 2018-02-15T06:43:08Z DEBUG ipawinsyncdefaultgroupfilter: 2018-02-15T06:43:08Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2018-02-15T06:43:08Z DEBUG ipawinsyncforcesync: 2018-02-15T06:43:08Z DEBUG true 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG FreeIPA/1.0 2018-02-15T06:43:08Z DEBUG ipawinsyncrealmattr: 2018-02-15T06:43:08Z DEBUG cn 2018-02-15T06:43:08Z DEBUG ipawinsyncacctdisable: 2018-02-15T06:43:08Z DEBUG both 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipa_winsync_plugin_init 2018-02-15T06:43:08Z DEBUG ipawinsyncnewentryfilter: 2018-02-15T06:43:08Z DEBUG (cn=ipaConfig) 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG FreeIPA project 2018-02-15T06:43:08Z DEBUG ipawinsyncdefaultgroupattr: 2018-02-15T06:43:08Z DEBUG ipaDefaultPrimaryGroup 2018-02-15T06:43:08Z DEBUG ipawinsyncrealmfilter: 2018-02-15T06:43:08Z DEBUG (objectclass=krbRealmContainer) 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG ipa winsync plugin 2018-02-15T06:43:08Z DEBUG ipawinsyncloginshellattr: 2018-02-15T06:43:08Z DEBUG ipaDefaultLoginShell 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG ipa-winsync-plugin 2018-02-15T06:43:08Z DEBUG ipawinsyncuserattr: 2018-02-15T06:43:08Z DEBUG uidNumber -1 2018-02-15T06:43:08Z DEBUG gidNumber -1 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [] 2018-02-15T06:43:08Z DEBUG only: updated value [u'60'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ipa-winsync 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG ipawinsynchomedirattr: 2018-02-15T06:43:08Z DEBUG ipaHomesRootDir 2018-02-15T06:43:08Z DEBUG ipawinsyncnewuserocattr: 2018-02-15T06:43:08Z DEBUG ipauserobjectclasses 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_winsync 2018-02-15T06:43:08Z DEBUG ipawinsyncuserflatten: 2018-02-15T06:43:08Z DEBUG true 2018-02-15T06:43:08Z DEBUG ipawinsyncdefaultgroupfilter: 2018-02-15T06:43:08Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2018-02-15T06:43:08Z DEBUG ipawinsyncforcesync: 2018-02-15T06:43:08Z DEBUG true 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG FreeIPA/1.0 2018-02-15T06:43:08Z DEBUG ipawinsyncrealmattr: 2018-02-15T06:43:08Z DEBUG cn 2018-02-15T06:43:08Z DEBUG ipawinsyncacctdisable: 2018-02-15T06:43:08Z DEBUG both 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipa_winsync_plugin_init 2018-02-15T06:43:08Z DEBUG ipawinsyncnewentryfilter: 2018-02-15T06:43:08Z DEBUG (cn=ipaConfig) 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG FreeIPA project 2018-02-15T06:43:08Z DEBUG ipawinsyncdefaultgroupattr: 2018-02-15T06:43:08Z DEBUG ipaDefaultPrimaryGroup 2018-02-15T06:43:08Z DEBUG ipawinsyncrealmfilter: 2018-02-15T06:43:08Z DEBUG (objectclass=krbRealmContainer) 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG ipa winsync plugin 2018-02-15T06:43:08Z DEBUG ipawinsyncloginshellattr: 2018-02-15T06:43:08Z DEBUG ipaDefaultLoginShell 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG ipa-winsync-plugin 2018-02-15T06:43:08Z DEBUG ipawinsyncuserattr: 2018-02-15T06:43:08Z DEBUG uidNumber -1 2018-02-15T06:43:08Z DEBUG gidNumber -1 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPrecedence: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG [(2, u'nsslapd-pluginPrecedence', [u'60'])] 2018-02-15T06:43:08Z DEBUG Updated 1 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG only: set nsslapd-sasl-mapping-fallback to 'on', current value [u'on'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2018-02-15T06:43:08Z DEBUG nsSaslMapPriority: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Full Principal 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSaslMapping 2018-02-15T06:43:08Z DEBUG nsSaslMapRegexString: 2018-02-15T06:43:08Z DEBUG \(.*\)@\(.*\) 2018-02-15T06:43:08Z DEBUG nsSaslMapBaseDNTemplate: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsSaslMapFilterTemplate: 2018-02-15T06:43:08Z DEBUG (krbPrincipalName=\1@\2) 2018-02-15T06:43:08Z DEBUG addifnew: '10' to nsSaslMapPriority, current value [u'10'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2018-02-15T06:43:08Z DEBUG nsSaslMapPriority: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Full Principal 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSaslMapping 2018-02-15T06:43:08Z DEBUG nsSaslMapRegexString: 2018-02-15T06:43:08Z DEBUG \(.*\)@\(.*\) 2018-02-15T06:43:08Z DEBUG nsSaslMapBaseDNTemplate: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsSaslMapFilterTemplate: 2018-02-15T06:43:08Z DEBUG (krbPrincipalName=\1@\2) 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Name Only,cn=mapping,cn=sasl,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2018-02-15T06:43:08Z DEBUG nsSaslMapPriority: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Name Only 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSaslMapping 2018-02-15T06:43:08Z DEBUG nsSaslMapRegexString: 2018-02-15T06:43:08Z DEBUG ^[^:@]+$ 2018-02-15T06:43:08Z DEBUG nsSaslMapBaseDNTemplate: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsSaslMapFilterTemplate: 2018-02-15T06:43:08Z DEBUG (krbPrincipalName=&@PYTEST.TEST) 2018-02-15T06:43:08Z DEBUG addifnew: '10' to nsSaslMapPriority, current value [u'10'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2018-02-15T06:43:08Z DEBUG nsSaslMapPriority: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Name Only 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSaslMapping 2018-02-15T06:43:08Z DEBUG nsSaslMapRegexString: 2018-02-15T06:43:08Z DEBUG ^[^:@]+$ 2018-02-15T06:43:08Z DEBUG nsSaslMapBaseDNTemplate: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsSaslMapFilterTemplate: 2018-02-15T06:43:08Z DEBUG (krbPrincipalName=&@PYTEST.TEST) 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG only: set nsslapd-sasl-max-buffer-size to '2097152', current value [u'2097152'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'2097152'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG only: set nsslapd-allow-hashed-passwords to 'on', current value [u'off'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG [(2, u'nsslapd-allow-hashed-passwords', [u'on'])] 2018-02-15T06:43:08Z DEBUG Updated 1 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG only: set nsslapd-ioblocktimeout to '10000', current value [u'300000'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'10000'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-betype: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG nsslapd-nagle: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:08Z DEBUG 64 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 500 2018-02-15T06:43:08Z DEBUG passwordMinAlphas: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-readonly: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:08Z DEBUG allowed 2018-02-15T06:43:08Z DEBUG passwordMinUppers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin: 2018-02-15T06:43:08Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:08Z DEBUG 20971520 2018-02-15T06:43:08Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMinAge: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordInHistory: 2018-02-15T06:43:08Z DEBUG 6 2018-02-15T06:43:08Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:08Z DEBUG 8192 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG passwordMaxAge: 2018-02-15T06:43:08Z DEBUG 8640000 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:08Z DEBUG gidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG day 2018-02-15T06:43:08Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:08Z DEBUG /tmp 2018-02-15T06:43:08Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-counters: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-minssf: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:08Z DEBUG nsslapd-localuser: 2018-02-15T06:43:08Z DEBUG dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-security: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordChange: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:08Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:08Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:08Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:08Z DEBUG passwordMaxFailure: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:08Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:08Z DEBUG 128 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:08Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:08Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordMustChange: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordExp: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:08Z DEBUG dirsrv-log 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:08Z DEBUG cn=Directory Manager 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinLength: 2018-02-15T06:43:08Z DEBUG 8 2018-02-15T06:43:08Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:08Z DEBUG week 2018-02-15T06:43:08Z DEBUG nsslapd-securePort: 2018-02-15T06:43:08Z DEBUG 636 2018-02-15T06:43:08Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG config 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapdConfig 2018-02-15T06:43:08Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:08Z DEBUG next 2018-02-15T06:43:08Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:08Z DEBUG -10 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordGraceLimit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG passwordWarning: 2018-02-15T06:43:08Z DEBUG 86400 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-config: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:08Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:08Z DEBUG 256 2018-02-15T06:43:08Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG passwordLockout: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:08Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-certdir: 2018-02-15T06:43:08Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 10 2018-02-15T06:43:08Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:08Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:08Z DEBUG 16 2018-02-15T06:43:08Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-localhost: 2018-02-15T06:43:08Z DEBUG replica3.pytest.test 2018-02-15T06:43:08Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:08Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:08Z DEBUG passwordMin8bit: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:08Z DEBUG uidNumber 2018-02-15T06:43:08Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:08Z DEBUG warn 2018-02-15T06:43:08Z DEBUG passwordMinCategories: 2018-02-15T06:43:08Z DEBUG 3 2018-02-15T06:43:08Z DEBUG passwordMinLowers: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordAdminDN: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordMinSpecials: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:08Z DEBUG -1 2018-02-15T06:43:08Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:08Z DEBUG month 2018-02-15T06:43:08Z DEBUG passwordUnlock: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:08Z DEBUG dc=example,dc=com 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-localssf: 2018-02-15T06:43:08Z DEBUG 71 2018-02-15T06:43:08Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:08Z DEBUG 2000 2018-02-15T06:43:08Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:08Z DEBUG 2097152 2018-02-15T06:43:08Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:08Z DEBUG 3600 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-port: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:08Z DEBUG 100 2018-02-15T06:43:08Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:08Z DEBUG cn=schema 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG cn=monitor 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:08Z DEBUG 600 2018-02-15T06:43:08Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:08Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:08Z DEBUG 300000 2018-02-15T06:43:08Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:08Z DEBUG 2018-02-15T06:43:08Z DEBUG nsslapd-rundir: 2018-02-15T06:43:08Z DEBUG /var/run/dirsrv 2018-02-15T06:43:08Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:08Z DEBUG replication-only 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:08Z DEBUG 16384 2018-02-15T06:43:08Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:08Z DEBUG 10000 2018-02-15T06:43:08Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG passwordMinDigits: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:08Z DEBUG 5 2018-02-15T06:43:08Z DEBUG passwordStorageScheme: 2018-02-15T06:43:08Z DEBUG SSHA512 2018-02-15T06:43:08Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG [(2, u'nsslapd-ioblocktimeout', [u'10000'])] 2018-02-15T06:43:08Z DEBUG Updated 1 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Parsing update file '/usr/share/ipa/updates/10-enable-betxn.update' 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NS7bitAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG 7-bit check 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NS7bitAttr_Init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce 7-bit clean attribute values 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginarg0: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG nsslapd-pluginarg3: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginarg2: 2018-02-15T06:43:08Z DEBUG , 2018-02-15T06:43:08Z DEBUG nsslapd-pluginarg1: 2018-02-15T06:43:08Z DEBUG mail 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NS7bitAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG 7-bit check 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NS7bitAttr_Init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce 7-bit clean attribute values 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginarg0: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG nsslapd-pluginarg3: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginarg2: 2018-02-15T06:43:08Z DEBUG , 2018-02-15T06:43:08Z DEBUG nsslapd-pluginarg1: 2018-02-15T06:43:08Z DEBUG mail 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=attribute uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG attribute uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG attribute uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG Auto Membership 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Auto Membership Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Auto Membership plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libautomember-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginConfigArea: 2018-02-15T06:43:08Z DEBUG cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG automember_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG Auto Membership 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Auto Membership Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Auto Membership plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libautomember-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginConfigArea: 2018-02-15T06:43:08Z DEBUG cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG automember_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG Linked Attributes 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Linked Attributes 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Linked Attributes plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG liblinkedattrs-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG linked_attrs_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG Linked Attributes 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Linked Attributes 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Linked Attributes plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG liblinkedattrs-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG linked_attrs_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Managed Entries plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libmanagedentries-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginConfigArea: 2018-02-15T06:43:08Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG mep_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Managed Entries plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libmanagedentries-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginConfigArea: 2018-02-15T06:43:08Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG mep_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG memberof 2018-02-15T06:43:08Z DEBUG memberofgroupattr: 2018-02-15T06:43:08Z DEBUG member 2018-02-15T06:43:08Z DEBUG memberUser 2018-02-15T06:43:08Z DEBUG memberHost 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG MemberOf Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG memberof plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libmemberof-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG memberofattr: 2018-02-15T06:43:08Z DEBUG memberOf 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG memberof_postop_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value [u'betxnpostoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpostoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG memberof 2018-02-15T06:43:08Z DEBUG memberofgroupattr: 2018-02-15T06:43:08Z DEBUG member 2018-02-15T06:43:08Z DEBUG memberUser 2018-02-15T06:43:08Z DEBUG memberHost 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG MemberOf Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG memberof plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libmemberof-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG memberofattr: 2018-02-15T06:43:08Z DEBUG memberOf 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG memberof_postop_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Multimaster Replication Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG replication_multimaster_plugin_init 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG AES 2018-02-15T06:43:08Z DEBUG Class of Service 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Multi-master Replication Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libreplication-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG replication-multimaster 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG object 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Multimaster Replication Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG replication_multimaster_plugin_init 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:43:08Z DEBUG ldbm database 2018-02-15T06:43:08Z DEBUG AES 2018-02-15T06:43:08Z DEBUG Class of Service 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Multi-master Replication Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libreplication-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG replication-multimaster 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG object 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=PAM Pass Through Auth,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG pamFallback: 2018-02-15T06:43:08Z DEBUG FALSE 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG PAM Pass Through Auth 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG pamExcludeSuffix: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG pamMissingSuffix: 2018-02-15T06:43:08Z DEBUG ALLOW 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libpam-passthru-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG pamConfig 2018-02-15T06:43:08Z DEBUG pamIDMapMethod: 2018-02-15T06:43:08Z DEBUG RDN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG pamIDAttr: 2018-02-15T06:43:08Z DEBUG notUsedWithRDNMethod 2018-02-15T06:43:08Z DEBUG pamSecure: 2018-02-15T06:43:08Z DEBUG TRUE 2018-02-15T06:43:08Z DEBUG pamService: 2018-02-15T06:43:08Z DEBUG ldapserver 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginloadglobal: 2018-02-15T06:43:08Z DEBUG true 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG pam_passthruauth_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpreoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG pamFallback: 2018-02-15T06:43:08Z DEBUG FALSE 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG PAM Pass Through Auth 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG pamExcludeSuffix: 2018-02-15T06:43:08Z DEBUG cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG pamMissingSuffix: 2018-02-15T06:43:08Z DEBUG ALLOW 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG off 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libpam-passthru-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG pamConfig 2018-02-15T06:43:08Z DEBUG pamIDMapMethod: 2018-02-15T06:43:08Z DEBUG RDN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG none 2018-02-15T06:43:08Z DEBUG pamIDAttr: 2018-02-15T06:43:08Z DEBUG notUsedWithRDNMethod 2018-02-15T06:43:08Z DEBUG pamSecure: 2018-02-15T06:43:08Z DEBUG TRUE 2018-02-15T06:43:08Z DEBUG pamService: 2018-02-15T06:43:08Z DEBUG ldapserver 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginloadglobal: 2018-02-15T06:43:08Z DEBUG true 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG pam_passthruauth_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG referint 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG referential integrity postoperation 2018-02-15T06:43:08Z DEBUG referint-update-delay: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG referential integrity plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libreferint-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG referint-logfile: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/referint 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG referint-membership-attr: 2018-02-15T06:43:08Z DEBUG member 2018-02-15T06:43:08Z DEBUG uniquemember 2018-02-15T06:43:08Z DEBUG owner 2018-02-15T06:43:08Z DEBUG seeAlso 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG referint_postop_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value [u'betxnpostoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpostoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG referint 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG referential integrity postoperation 2018-02-15T06:43:08Z DEBUG referint-update-delay: 2018-02-15T06:43:08Z DEBUG 0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG referential integrity plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libreferint-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:43:08Z DEBUG 40 2018-02-15T06:43:08Z DEBUG referint-logfile: 2018-02-15T06:43:08Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/referint 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG referint-membership-attr: 2018-02-15T06:43:08Z DEBUG member 2018-02-15T06:43:08Z DEBUG uniquemember 2018-02-15T06:43:08Z DEBUG owner 2018-02-15T06:43:08Z DEBUG seeAlso 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG referint_postop_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Roles Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:43:08Z DEBUG State Change Plugin 2018-02-15T06:43:08Z DEBUG Views 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG roles plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libroles-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG roles 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG roles_init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG object 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Roles Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:43:08Z DEBUG State Change Plugin 2018-02-15T06:43:08Z DEBUG Views 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG roles plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libroles-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG roles 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG roles_init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG object 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG statechange 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG State Change Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG state change notification service plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libstatechange-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG statechange_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value [u'betxnpostoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpostoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG statechange 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG State Change Plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG state change notification service plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libstatechange-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG statechange_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=USN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=USN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG USN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG USN (Update Sequence Number) plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libusn-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG USN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG usn_init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG object 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=USN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG USN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG USN (Update Sequence Number) plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libusn-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG USN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG usn_init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG object 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG IPA MODRDN 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG IPA MODRDN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG IPA MODRDN plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_modrdn 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Red Hat, Inc. 2018-02-15T06:43:08Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipamodrdn_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-plugintype to 'betxnpostoperation', current value [u'betxnpostoperation'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'betxnpostoperation'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG IPA MODRDN 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG IPA MODRDN 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG IPA MODRDN plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_modrdn 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Red Hat, Inc. 2018-02-15T06:43:08Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:43:08Z DEBUG 60 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpostoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipamodrdn_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ipa_pwd_extop 2018-02-15T06:43:08Z DEBUG nsslapd-realmtree: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG FreeIPA/1.0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG IPA Password Extended Operation plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_pwd_extop 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG IPA Password Manager 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipapwd_init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG extendedop 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG FreeIPA project 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ipa_pwd_extop 2018-02-15T06:43:08Z DEBUG nsslapd-realmtree: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG FreeIPA/1.0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG IPA Password Extended Operation plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_pwd_extop 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG IPA Password Manager 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipapwd_init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG extendedop 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG FreeIPA project 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG New entry: cn=NIS Server,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG Parsing update file '/usr/share/ipa/updates/10-ipapwd.update' 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ipa_pwd_extop 2018-02-15T06:43:08Z DEBUG nsslapd-realmtree: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG FreeIPA/1.0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG IPA Password Extended Operation plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_pwd_extop 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG IPA Password Manager 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipapwd_init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG extendedop 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG FreeIPA project 2018-02-15T06:43:08Z DEBUG add: '49' to nsslapd-pluginprecedence, current value [] 2018-02-15T06:43:08Z DEBUG add: updated value [u'49'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ipa_pwd_extop 2018-02-15T06:43:08Z DEBUG nsslapd-realmtree: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG FreeIPA/1.0 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG IPA Password Extended Operation plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libipa_pwd_extop 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG IPA Password Manager 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG ipapwd_init 2018-02-15T06:43:08Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:43:08Z DEBUG 49 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG extendedop 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG FreeIPA project 2018-02-15T06:43:08Z DEBUG [(2, u'nsslapd-pluginprecedence', [u'49'])] 2018-02-15T06:43:08Z DEBUG Updated 1 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Parsing update file '/usr/share/ipa/updates/10-rootdse.update' 2018-02-15T06:43:08Z DEBUG Updating existing entry: 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: 2018-02-15T06:43:08Z DEBUG netscapemdsuffix: 2018-02-15T06:43:08Z DEBUG cn=ldap://dc=replica3,dc=pytest,dc=test:0 2018-02-15T06:43:08Z DEBUG ipaDomainLevel: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG aci: 2018-02-15T06:43:08Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2018-02-15T06:43:08Z DEBUG dataversion: 2018-02-15T06:43:08Z DEBUG 020180215064306 2018-02-15T06:43:08Z DEBUG lastusn: 2018-02-15T06:43:08Z DEBUG 50 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG ipatopologyismanaged: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG ipatopologypluginversion: 2018-02-15T06:43:08Z DEBUG 1.0 2018-02-15T06:43:08Z DEBUG add: 'namingContexts' to nsslapd-return-default-opattr, current value [] 2018-02-15T06:43:08Z DEBUG add: updated value [u'namingContexts'] 2018-02-15T06:43:08Z DEBUG add: 'supportedControl' to nsslapd-return-default-opattr, current value [u'namingContexts'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'namingContexts', u'supportedControl'] 2018-02-15T06:43:08Z DEBUG add: 'supportedExtension' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension'] 2018-02-15T06:43:08Z DEBUG add: 'supportedLDAPVersion' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion'] 2018-02-15T06:43:08Z DEBUG add: 'supportedSASLMechanisms' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms'] 2018-02-15T06:43:08Z DEBUG add: 'vendorName' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName'] 2018-02-15T06:43:08Z DEBUG add: 'vendorVersion' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName', u'vendorVersion'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: 2018-02-15T06:43:08Z DEBUG netscapemdsuffix: 2018-02-15T06:43:08Z DEBUG cn=ldap://dc=replica3,dc=pytest,dc=test:0 2018-02-15T06:43:08Z DEBUG ipaDomainLevel: 2018-02-15T06:43:08Z DEBUG 1 2018-02-15T06:43:08Z DEBUG aci: 2018-02-15T06:43:08Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2018-02-15T06:43:08Z DEBUG dataversion: 2018-02-15T06:43:08Z DEBUG 020180215064306 2018-02-15T06:43:08Z DEBUG lastusn: 2018-02-15T06:43:08Z DEBUG 50 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG defaultnamingcontext: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG ipatopologyismanaged: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-return-default-opattr: 2018-02-15T06:43:08Z DEBUG namingContexts 2018-02-15T06:43:08Z DEBUG supportedControl 2018-02-15T06:43:08Z DEBUG supportedExtension 2018-02-15T06:43:08Z DEBUG supportedLDAPVersion 2018-02-15T06:43:08Z DEBUG supportedSASLMechanisms 2018-02-15T06:43:08Z DEBUG vendorName 2018-02-15T06:43:08Z DEBUG vendorVersion 2018-02-15T06:43:08Z DEBUG ipatopologypluginversion: 2018-02-15T06:43:08Z DEBUG 1.0 2018-02-15T06:43:08Z DEBUG [(2, u'nsslapd-return-default-opattr', [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName', u'vendorVersion'])] 2018-02-15T06:43:08Z DEBUG Updated 1 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Parsing update file '/usr/share/ipa/updates/10-selinuxusermap.update' 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=selinux,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=selinux,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG selinux 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=selinux,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG selinux 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=usermap,cn=selinux,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=usermap,cn=selinux,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG aci: 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Add SELinux User Maps";allow (add) groupdn = "ldap:///cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "cn || ipaenabledflag || ipaselinuxuser || memberhost || memberuser || seealso")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Modify SELinux User Maps";allow (write) groupdn = "ldap:///cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "accesstime || cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipaselinuxuser || ipauniqueid || member || memberhost || memberuser || modifytimestamp || objectclass || seealso || usercategory")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Read SELinux User Maps";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Remove SELinux User Maps";allow (delete) groupdn = "ldap:///cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG usermap 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=usermap,cn=selinux,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG aci: 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Add SELinux User Maps";allow (add) groupdn = "ldap:///cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "cn || ipaenabledflag || ipaselinuxuser || memberhost || memberuser || seealso")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Modify SELinux User Maps";allow (write) groupdn = "ldap:///cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "accesstime || cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipaselinuxuser || ipauniqueid || member || memberhost || memberuser || modifytimestamp || objectclass || seealso || usercategory")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Read SELinux User Maps";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Remove SELinux User Maps";allow (delete) groupdn = "ldap:///cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG usermap 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Parsing update file '/usr/share/ipa/updates/10-uniqueness.update' 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=sudorule name uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG cn 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG sudorule name uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG cn=sudorules,cn=sudo,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG cn 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG sudorule name uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG cn=sudorules,cn=sudo,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG New entry: cn=certificate store subject uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG ipaCertSubject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG certificate store subject uniqueness 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.1.0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Fedora Project 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG ipaCertSubject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG certificate store subject uniqueness 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.1.0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Fedora Project 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG New entry: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG ipaCertIssuerSerial 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG certificate store issuer/serial uniqueness 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.1.0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Fedora Project 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG ipaCertIssuerSerial 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG certificate store issuer/serial uniqueness 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.1.0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Fedora Project 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG New entry: cn=uid uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG uniqueness-subtree-entries-oc: 2018-02-15T06:43:08Z DEBUG posixAccount 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG uid uniqueness 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.1.0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Fedora Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=compat,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG uniqueness-subtree-entries-oc: 2018-02-15T06:43:08Z DEBUG posixAccount 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG uid uniqueness 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.1.0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Fedora Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=compat,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=uid uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG uniqueness-subtree-entries-oc: 2018-02-15T06:43:08Z DEBUG posixAccount 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG uid uniqueness 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.1.0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Fedora Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=compat,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG add: 'cn=compat,dc=pytest,dc=test' to uniqueness-exclude-subtrees, current value [u'cn=compat,dc=pytest,dc=test', u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test', u'cn=compat,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test', u'cn=compat,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'cn=compat,dc=pytest,dc=test', u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG remove: 'off' from uniqueness-across-all-subtrees, current value [u'on'] 2018-02-15T06:43:08Z DEBUG remove: 'off' not in uniqueness-across-all-subtrees 2018-02-15T06:43:08Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG add: 'posixAccount' to uniqueness-subtree-entries-oc, current value [u'posixAccount'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'posixAccount'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG uid 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG uniqueness-subtree-entries-oc: 2018-02-15T06:43:08Z DEBUG posixAccount 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG uid uniqueness 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.1.0 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG Fedora Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=compat,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG krbPrincipalName 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG krbPrincipalName uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG krbPrincipalName 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG krbPrincipalName uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG krbCanonicalName 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG krbCanonicalName uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG krbCanonicalName 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG krbCanonicalName uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG ipaUniqueID 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ipaUniqueID uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'on'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG uniqueness-attribute-name: 2018-02-15T06:43:08Z DEBUG ipaUniqueID 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ipaUniqueID uniqueness 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Enforce unique attribute values 2018-02-15T06:43:08Z DEBUG uniqueness-across-all-subtrees: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libattr-unique-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG uniqueness-exclude-subtrees: 2018-02-15T06:43:08Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG uniqueness-subtrees: 2018-02-15T06:43:08Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG preoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG NSUniqueAttr_Init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Parsing update file '/usr/share/ipa/updates/19-managed-entries.update' 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Managed Entries plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libmanagedentries-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginConfigArea: 2018-02-15T06:43:08Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG mep_init 2018-02-15T06:43:08Z DEBUG only: set nsslapd-pluginConfigArea to 'cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test', current value [u'cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG only: updated value [u'cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2018-02-15T06:43:08Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:08Z DEBUG 1.3.7.5 2018-02-15T06:43:08Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:08Z DEBUG Managed Entries plugin 2018-02-15T06:43:08Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:08Z DEBUG on 2018-02-15T06:43:08Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:08Z DEBUG libmanagedentries-plugin 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsSlapdPlugin 2018-02-15T06:43:08Z DEBUG extensibleObject 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:08Z DEBUG database 2018-02-15T06:43:08Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:08Z DEBUG 389 Project 2018-02-15T06:43:08Z DEBUG nsslapd-pluginConfigArea: 2018-02-15T06:43:08Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:08Z DEBUG betxnpreoperation 2018-02-15T06:43:08Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:08Z DEBUG mep_init 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Managed Entries 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Templates 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Templates 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Definitions 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG Definitions 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Parsing update file '/usr/share/ipa/updates/20-aci.update' 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=ng,cn=alt,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=ng,cn=alt,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG aci: 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ng 2018-02-15T06:43:08Z DEBUG add: '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)' to aci, current value [u'(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=ng,cn=alt,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG aci: 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG ng 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG aci: 2018-02-15T06:43:08Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG accounts 2018-02-15T06:43:08Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2018-02-15T06:43:08Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Final value after applying updates 2018-02-15T06:43:08Z DEBUG dn: cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG nsContainer 2018-02-15T06:43:08Z DEBUG aci: 2018-02-15T06:43:08Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2018-02-15T06:43:08Z DEBUG cn: 2018-02-15T06:43:08Z DEBUG accounts 2018-02-15T06:43:08Z DEBUG [] 2018-02-15T06:43:08Z DEBUG Updated 0 2018-02-15T06:43:08Z DEBUG Done 2018-02-15T06:43:08Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG --------------------------------------------- 2018-02-15T06:43:08Z DEBUG Initial value 2018-02-15T06:43:08Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:08Z DEBUG info: 2018-02-15T06:43:08Z DEBUG IPA V2.0 2018-02-15T06:43:08Z DEBUG objectClass: 2018-02-15T06:43:08Z DEBUG top 2018-02-15T06:43:08Z DEBUG domain 2018-02-15T06:43:08Z DEBUG pilotObject 2018-02-15T06:43:08Z DEBUG domainRelatedObject 2018-02-15T06:43:08Z DEBUG nisDomainObject 2018-02-15T06:43:08Z DEBUG associatedDomain: 2018-02-15T06:43:08Z DEBUG pytest.test 2018-02-15T06:43:08Z DEBUG dc: 2018-02-15T06:43:08Z DEBUG pytest 2018-02-15T06:43:08Z DEBUG nisDomain: 2018-02-15T06:43:08Z DEBUG pytest.test 2018-02-15T06:43:08Z DEBUG aci: 2018-02-15T06:43:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:08Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:08Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:08Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:08Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:08Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:08Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:08Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:08Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:08Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:08Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG add: '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG computers 2018-02-15T06:43:09Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)' to aci, current value [u'(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG computers 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG computers 2018-02-15T06:43:09Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)' to aci, current value [u'(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG computers 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG add: '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG add: '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG replicas 2018-02-15T06:43:09Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' not in aci 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG replicas 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG masters 2018-02-15T06:43:09Z DEBUG add: '(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG masters 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG masters 2018-02-15T06:43:09Z DEBUG add: '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG masters 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG sysaccounts 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG sysaccounts 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG kerberos 2018-02-15T06:43:09Z DEBUG add: '(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)' to aci, current value [u'(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG kerberos 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG add: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG add: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=tasks,cn=config 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=tasks,cn=config 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG tasks 2018-02-15T06:43:09Z DEBUG add: '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=tasks,cn=config 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG tasks 2018-02-15T06:43:09Z DEBUG [(0, u'aci', [u'(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'])] 2018-02-15T06:43:09Z DEBUG Updated 1 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG mapping tree 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG mapping tree 2018-02-15T06:43:09Z DEBUG [(0, u'aci', [u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'])] 2018-02-15T06:43:09Z DEBUG Updated 1 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG mapping tree 2018-02-15T06:43:09Z DEBUG add: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG mapping tree 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=dc\=pytest\,dc\=test,cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=dc\=pytest\,dc\=test,cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-state: 2018-02-15T06:43:09Z DEBUG backend 2018-02-15T06:43:09Z DEBUG nsslapd-referral: 2018-02-15T06:43:09Z DEBUG ldap://replica3.pytest.test:389/dc%3Dpytest%2Cdc%3Dtest 2018-02-15T06:43:09Z DEBUG ldap://master.pytest.test:389/dc%3Dpytest%2Cdc%3Dtest 2018-02-15T06:43:09Z DEBUG ldap://replica.pytest.test:389/dc%3Dpytest%2Cdc%3Dtest 2018-02-15T06:43:09Z DEBUG ldap://replica2.pytest.test:389/dc%3Dpytest%2Cdc%3Dtest 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG "dc=pytest,dc=test" 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG nsMappingTree 2018-02-15T06:43:09Z DEBUG nsslapd-backend: 2018-02-15T06:43:09Z DEBUG userRoot 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=dc\=pytest\,dc\=test,cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-state: 2018-02-15T06:43:09Z DEBUG backend 2018-02-15T06:43:09Z DEBUG nsslapd-referral: 2018-02-15T06:43:09Z DEBUG ldap://replica3.pytest.test:389/dc%3Dpytest%2Cdc%3Dtest 2018-02-15T06:43:09Z DEBUG ldap://master.pytest.test:389/dc%3Dpytest%2Cdc%3Dtest 2018-02-15T06:43:09Z DEBUG ldap://replica.pytest.test:389/dc%3Dpytest%2Cdc%3Dtest 2018-02-15T06:43:09Z DEBUG ldap://replica2.pytest.test:389/dc%3Dpytest%2Cdc%3Dtest 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG "dc=pytest,dc=test" 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG nsMappingTree 2018-02-15T06:43:09Z DEBUG nsslapd-backend: 2018-02-15T06:43:09Z DEBUG userRoot 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG New entry: cn=o\=ipaca,cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=config 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-betype: 2018-02-15T06:43:09Z DEBUG ldbm database 2018-02-15T06:43:09Z DEBUG nsslapd-nagle: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:09Z DEBUG 64 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:09Z DEBUG 500 2018-02-15T06:43:09Z DEBUG passwordMinAlphas: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-readonly: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:09Z DEBUG allowed 2018-02-15T06:43:09Z DEBUG passwordMinUppers: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-plugin: 2018-02-15T06:43:09Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:09Z DEBUG 2097152 2018-02-15T06:43:09Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:09Z DEBUG 20971520 2018-02-15T06:43:09Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:09Z DEBUG 3600 2018-02-15T06:43:09Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:09Z DEBUG 3 2018-02-15T06:43:09Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:09Z DEBUG -10 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:09Z DEBUG week 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG passwordMinAge: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:09Z DEBUG week 2018-02-15T06:43:09Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:09Z DEBUG 60 2018-02-15T06:43:09Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:09Z DEBUG 8192 2018-02-15T06:43:09Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordInHistory: 2018-02-15T06:43:09Z DEBUG 6 2018-02-15T06:43:09Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:09Z DEBUG 8192 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:09Z DEBUG month 2018-02-15T06:43:09Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG passwordMaxAge: 2018-02-15T06:43:09Z DEBUG 8640000 2018-02-15T06:43:09Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:09Z DEBUG gidNumber 2018-02-15T06:43:09Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:09Z DEBUG day 2018-02-15T06:43:09Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:09Z DEBUG /tmp 2018-02-15T06:43:09Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-counters: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:09Z DEBUG month 2018-02-15T06:43:09Z DEBUG nsslapd-minssf: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:09Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:09Z DEBUG nsslapd-localuser: 2018-02-15T06:43:09Z DEBUG dirsrv 2018-02-15T06:43:09Z DEBUG nsslapd-security: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordChange: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:09Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:09Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:09Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:09Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:09Z DEBUG passwordMaxFailure: 2018-02-15T06:43:09Z DEBUG 3 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:09Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:09Z DEBUG 128 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:09Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:09Z DEBUG cn=Directory Manager 2018-02-15T06:43:09Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:09Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:09Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG passwordMustChange: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordExp: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:09Z DEBUG dirsrv-log 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:09Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:09Z DEBUG cn=Directory Manager 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordMinLength: 2018-02-15T06:43:09Z DEBUG 8 2018-02-15T06:43:09Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:09Z DEBUG -10 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:09Z DEBUG week 2018-02-15T06:43:09Z DEBUG nsslapd-securePort: 2018-02-15T06:43:09Z DEBUG 636 2018-02-15T06:43:09Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG config 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG nsslapdConfig 2018-02-15T06:43:09Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:09Z DEBUG next 2018-02-15T06:43:09Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:09Z DEBUG -10 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordGraceLimit: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG passwordWarning: 2018-02-15T06:43:09Z DEBUG 86400 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:09Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:09Z DEBUG nsslapd-config: 2018-02-15T06:43:09Z DEBUG cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:09Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:09Z DEBUG 256 2018-02-15T06:43:09Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:09Z DEBUG 2097152 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:09Z DEBUG month 2018-02-15T06:43:09Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:09Z DEBUG SSHA512 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG passwordLockout: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:09Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:09Z DEBUG nsslapd-certdir: 2018-02-15T06:43:09Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:09Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:09Z DEBUG 10 2018-02-15T06:43:09Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:09Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:09Z DEBUG 16 2018-02-15T06:43:09Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-localhost: 2018-02-15T06:43:09Z DEBUG replica3.pytest.test 2018-02-15T06:43:09Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:09Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:09Z DEBUG passwordMin8bit: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:09Z DEBUG uidNumber 2018-02-15T06:43:09Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:09Z DEBUG warn 2018-02-15T06:43:09Z DEBUG passwordMinCategories: 2018-02-15T06:43:09Z DEBUG 3 2018-02-15T06:43:09Z DEBUG passwordMinLowers: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordAdminDN: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordMinSpecials: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:09Z DEBUG 40 2018-02-15T06:43:09Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:09Z DEBUG -1 2018-02-15T06:43:09Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:09Z DEBUG none 2018-02-15T06:43:09Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:09Z DEBUG month 2018-02-15T06:43:09Z DEBUG passwordUnlock: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:09Z DEBUG 2097152 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:09Z DEBUG dc=example,dc=com 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-localssf: 2018-02-15T06:43:09Z DEBUG 71 2018-02-15T06:43:09Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:09Z DEBUG 2000 2018-02-15T06:43:09Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:09Z DEBUG 2097152 2018-02-15T06:43:09Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:09Z DEBUG 3600 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-port: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:09Z DEBUG cn=schema 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG cn=monitor 2018-02-15T06:43:09Z DEBUG cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:09Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:09Z DEBUG 300000 2018-02-15T06:43:09Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-rundir: 2018-02-15T06:43:09Z DEBUG /var/run/dirsrv 2018-02-15T06:43:09Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:09Z DEBUG replication-only 2018-02-15T06:43:09Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:09Z DEBUG 16384 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:09Z DEBUG 10000 2018-02-15T06:43:09Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordMinDigits: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG passwordStorageScheme: 2018-02-15T06:43:09Z DEBUG SSHA512 2018-02-15T06:43:09Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-betype: 2018-02-15T06:43:09Z DEBUG ldbm database 2018-02-15T06:43:09Z DEBUG nsslapd-nagle: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-referralmode: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:43:09Z DEBUG 64 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:43:09Z DEBUG 500 2018-02-15T06:43:09Z DEBUG passwordMinAlphas: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-readonly: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordLegacyPolicy: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:43:09Z DEBUG allowed 2018-02-15T06:43:09Z DEBUG passwordMinUppers: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-plugin: 2018-02-15T06:43:09Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:43:09Z DEBUG 2097152 2018-02-15T06:43:09Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:43:09Z DEBUG 20971520 2018-02-15T06:43:09Z DEBUG nsslapd-timelimit: 2018-02-15T06:43:09Z DEBUG 3600 2018-02-15T06:43:09Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordMinTokenLength: 2018-02-15T06:43:09Z DEBUG 3 2018-02-15T06:43:09Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:43:09Z DEBUG -10 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:43:09Z DEBUG week 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG passwordMinAge: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:43:09Z DEBUG week 2018-02-15T06:43:09Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:43:09Z DEBUG 60 2018-02-15T06:43:09Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:43:09Z DEBUG 8192 2018-02-15T06:43:09Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordInHistory: 2018-02-15T06:43:09Z DEBUG 6 2018-02-15T06:43:09Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-conntablesize: 2018-02-15T06:43:09Z DEBUG 8192 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:43:09Z DEBUG month 2018-02-15T06:43:09Z DEBUG nsslapd-saslpath: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG passwordMaxAge: 2018-02-15T06:43:09Z DEBUG 8640000 2018-02-15T06:43:09Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:43:09Z DEBUG gidNumber 2018-02-15T06:43:09Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:43:09Z DEBUG day 2018-02-15T06:43:09Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-csnlogging: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-tmpdir: 2018-02-15T06:43:09Z DEBUG /tmp 2018-02-15T06:43:09Z DEBUG passwordResetFailureCount: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-counters: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-svrtab: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:43:09Z DEBUG month 2018-02-15T06:43:09Z DEBUG nsslapd-minssf: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-schemadir: 2018-02-15T06:43:09Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:43:09Z DEBUG nsslapd-localuser: 2018-02-15T06:43:09Z DEBUG dirsrv 2018-02-15T06:43:09Z DEBUG nsslapd-security: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordChange: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-port 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:43:09Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:43:09Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:43:09Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:43:09Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:43:09Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:43:09Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:43:09Z DEBUG passwordMaxFailure: 2018-02-15T06:43:09Z DEBUG 3 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:43:09Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:43:09Z DEBUG 128 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:43:09Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-rootdn: 2018-02-15T06:43:09Z DEBUG cn=Directory Manager 2018-02-15T06:43:09Z DEBUG nsslapd-ldifdir: 2018-02-15T06:43:09Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:43:09Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG passwordMustChange: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordExp: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG nsslapd-logging-backend: 2018-02-15T06:43:09Z DEBUG dirsrv-log 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:09Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:43:09Z DEBUG cn=Directory Manager 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordMinLength: 2018-02-15T06:43:09Z DEBUG 8 2018-02-15T06:43:09Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-idletimeout: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:43:09Z DEBUG -10 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:43:09Z DEBUG week 2018-02-15T06:43:09Z DEBUG nsslapd-securePort: 2018-02-15T06:43:09Z DEBUG 636 2018-02-15T06:43:09Z DEBUG nsslapd-snmp-index: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG config 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG nsslapdConfig 2018-02-15T06:43:09Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordSendExpiringTime: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-hash-filters: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:43:09Z DEBUG next 2018-02-15T06:43:09Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:43:09Z DEBUG -10 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-listenhost: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordCheckSyntax: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordGraceLimit: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG passwordWarning: 2018-02-15T06:43:09Z DEBUG 86400 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-instancedir: 2018-02-15T06:43:09Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:43:09Z DEBUG nsslapd-config: 2018-02-15T06:43:09Z DEBUG cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-versionstring: 2018-02-15T06:43:09Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:43:09Z DEBUG 256 2018-02-15T06:43:09Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:43:09Z DEBUG 2097152 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:43:09Z DEBUG month 2018-02-15T06:43:09Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:43:09Z DEBUG SSHA512 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG passwordLockout: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-lockdir: 2018-02-15T06:43:09Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:09Z DEBUG nsslapd-certdir: 2018-02-15T06:43:09Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:09Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:43:09Z DEBUG 10 2018-02-15T06:43:09Z DEBUG nsslapd-backendconfig: 2018-02-15T06:43:09Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-threadnumber: 2018-02-15T06:43:09Z DEBUG 16 2018-02-15T06:43:09Z DEBUG nsslapd-schemamod: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-localhost: 2018-02-15T06:43:09Z DEBUG replica3.pytest.test 2018-02-15T06:43:09Z DEBUG nsslapd-bakdir: 2018-02-15T06:43:09Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:43:09Z DEBUG passwordMin8bit: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:43:09Z DEBUG uidNumber 2018-02-15T06:43:09Z DEBUG nsslapd-validate-cert: 2018-02-15T06:43:09Z DEBUG warn 2018-02-15T06:43:09Z DEBUG passwordMinCategories: 2018-02-15T06:43:09Z DEBUG 3 2018-02-15T06:43:09Z DEBUG passwordMinLowers: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordAdminDN: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordMinSpecials: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-lastmod: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:43:09Z DEBUG 40 2018-02-15T06:43:09Z DEBUG passwordMaxRepeats: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:43:09Z DEBUG -1 2018-02-15T06:43:09Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:43:09Z DEBUG none 2018-02-15T06:43:09Z DEBUG nsslapd-result-tweak: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:43:09Z DEBUG month 2018-02-15T06:43:09Z DEBUG passwordUnlock: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-schemacheck: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-maxbersize: 2018-02-15T06:43:09Z DEBUG 2097152 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:43:09Z DEBUG dc=example,dc=com 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-localssf: 2018-02-15T06:43:09Z DEBUG 71 2018-02-15T06:43:09Z DEBUG nsslapd-sizelimit: 2018-02-15T06:43:09Z DEBUG 2000 2018-02-15T06:43:09Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:43:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:43:09Z DEBUG 2097152 2018-02-15T06:43:09Z DEBUG passwordLockoutDuration: 2018-02-15T06:43:09Z DEBUG 3600 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-port: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:43:09Z DEBUG 100 2018-02-15T06:43:09Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:43:09Z DEBUG cn=schema 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG cn=monitor 2018-02-15T06:43:09Z DEBUG cn=config 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:43:09Z DEBUG 1 2018-02-15T06:43:09Z DEBUG nsslapd-auditlog: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:43:09Z DEBUG 600 2018-02-15T06:43:09Z DEBUG nsslapd-rootpw: 2018-02-15T06:43:09Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:43:09Z DEBUG 300000 2018-02-15T06:43:09Z DEBUG nsslapd-workingdir: 2018-02-15T06:43:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:43:09Z DEBUG 2018-02-15T06:43:09Z DEBUG nsslapd-rundir: 2018-02-15T06:43:09Z DEBUG /var/run/dirsrv 2018-02-15T06:43:09Z DEBUG nsslapd-schemareplace: 2018-02-15T06:43:09Z DEBUG replication-only 2018-02-15T06:43:09Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:43:09Z DEBUG 16384 2018-02-15T06:43:09Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:43:09Z DEBUG 10000 2018-02-15T06:43:09Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:43:09Z DEBUG off 2018-02-15T06:43:09Z DEBUG passwordMinDigits: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:43:09Z DEBUG 5 2018-02-15T06:43:09Z DEBUG passwordStorageScheme: 2018-02-15T06:43:09Z DEBUG SSHA512 2018-02-15T06:43:09Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=pytest,dc=test")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=pytest,dc=test")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=pytest,dc=test")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=pytest,dc=test")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=hbac,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=hbac,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG hbac 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [u'(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";)'] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=hbac,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG hbac 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=sudo,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=sudo,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG sudo 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2018-02-15T06:43:09Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=sudo,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG sudo 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG accounts 2018-02-15T06:43:09Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG accounts 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG add: '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG info: 2018-02-15T06:43:09Z DEBUG IPA V2.0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG domain 2018-02-15T06:43:09Z DEBUG pilotObject 2018-02-15T06:43:09Z DEBUG domainRelatedObject 2018-02-15T06:43:09Z DEBUG nisDomainObject 2018-02-15T06:43:09Z DEBUG associatedDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG dc: 2018-02-15T06:43:09Z DEBUG pytest 2018-02-15T06:43:09Z DEBUG nisDomain: 2018-02-15T06:43:09Z DEBUG pytest.test 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:43:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG services 2018-02-15T06:43:09Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(target = "ldap:///krbprincipalname=*/($dn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(target = "ldap:///krbprincipalname=*/($dn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///krbprincipalname=*/($dn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=pytest,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG services 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=ranges,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ranges 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)' to aci, current value [u'(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)', u'(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=ranges,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ranges 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG sysaccounts 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG sysaccounts 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication,cn=etc,dc=pytest,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG etc 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=replication,cn=etc,dc=pytest,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=replication,cn=etc,dc=pytest,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";)', u'(target = "ldap:///cn=replication,cn=etc,dc=pytest,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=replication,cn=etc,dc=pytest,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG etc 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ipa 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ipa 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ipa 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ipa 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: krbPrincipalName=WELLKNOWN/ANONYMOUS@PYTEST.TEST,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@PYTEST.TEST,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbExtraData: 2018-02-15T06:43:09Z DEBUG AAI3zINacm9vdC9hZG1pbkBQWVRFU1QuVEVTVAA= 2018-02-15T06:43:09Z DEBUG krbCanonicalName: 2018-02-15T06:43:09Z DEBUG WELLKNOWN/ANONYMOUS@PYTEST.TEST 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbprincipal 2018-02-15T06:43:09Z DEBUG krbprincipalaux 2018-02-15T06:43:09Z DEBUG krbTicketPolicyAux 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG ipaAllowedOperations 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:43:09Z DEBUG ipaAllowedToPerform;read_keys: 2018-02-15T06:43:09Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPrincipalKey: 2018-02-15T06:43:09Z DEBUG XXXXXXXX 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference: 2018-02-15T06:43:09Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPrincipalName: 2018-02-15T06:43:09Z DEBUG WELLKNOWN/ANONYMOUS@PYTEST.TEST 2018-02-15T06:43:09Z DEBUG krbLastPwdChange: 2018-02-15T06:43:09Z DEBUG 20180214054215Z 2018-02-15T06:43:09Z DEBUG addifexist: 'ipaAllowedOperations' to objectclass, current value [u'krbprincipal', u'krbprincipalaux', u'krbTicketPolicyAux', u'top', u'ipaAllowedOperations'] 2018-02-15T06:43:09Z DEBUG addifexist: set objectclass to [u'krbprincipal', u'krbprincipalaux', u'krbTicketPolicyAux', u'top', u'ipaAllowedOperations', u'ipaAllowedOperations'] 2018-02-15T06:43:09Z DEBUG addifexist: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2018-02-15T06:43:09Z DEBUG addifexist: set aci to [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2018-02-15T06:43:09Z DEBUG addifexist: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test' to ipaAllowedToPerform;read_keys, current value [u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:43:09Z DEBUG addifexist: set ipaAllowedToPerform;read_keys to [u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test', u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@PYTEST.TEST,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbExtraData: 2018-02-15T06:43:09Z DEBUG AAI3zINacm9vdC9hZG1pbkBQWVRFU1QuVEVTVAA= 2018-02-15T06:43:09Z DEBUG krbCanonicalName: 2018-02-15T06:43:09Z DEBUG WELLKNOWN/ANONYMOUS@PYTEST.TEST 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbprincipal 2018-02-15T06:43:09Z DEBUG krbprincipalaux 2018-02-15T06:43:09Z DEBUG krbTicketPolicyAux 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG ipaAllowedOperations 2018-02-15T06:43:09Z DEBUG aci: 2018-02-15T06:43:09Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:43:09Z DEBUG ipaAllowedToPerform;read_keys: 2018-02-15T06:43:09Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPrincipalKey: 2018-02-15T06:43:09Z DEBUG XXXXXXXX 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference: 2018-02-15T06:43:09Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPrincipalName: 2018-02-15T06:43:09Z DEBUG WELLKNOWN/ANONYMOUS@PYTEST.TEST 2018-02-15T06:43:09Z DEBUG krbLastPwdChange: 2018-02-15T06:43:09Z DEBUG 20180214054215Z 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-default_password_policy.update' 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbMinPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdHistoryLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbPwdPolicy 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG krbPwdMinDiffChars: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMinLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdLockoutDuration: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMaxFailure: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbMaxPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdFailureCountInterval: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Host Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbMinPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdHistoryLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbPwdPolicy 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG krbPwdMinDiffChars: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMinLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdLockoutDuration: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMaxFailure: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbMaxPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdFailureCountInterval: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Host Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Default Service Password Policy,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbMinPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdHistoryLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbPwdPolicy 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG krbPwdMinDiffChars: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMinLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdLockoutDuration: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMaxFailure: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbMaxPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdFailureCountInterval: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Service Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbMinPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdHistoryLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbPwdPolicy 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG krbPwdMinDiffChars: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMinLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdLockoutDuration: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMaxFailure: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbMaxPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdFailureCountInterval: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Service Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Kerberos Service Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Kerberos Service Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbMinPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdHistoryLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbPwdPolicy 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG krbPwdMinDiffChars: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMinLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdLockoutDuration: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMaxFailure: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbMaxPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdFailureCountInterval: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Kerberos Service Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbMinPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdHistoryLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG krbPwdPolicy 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG krbPwdMinDiffChars: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMinLength: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdLockoutDuration: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdMaxFailure: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbMaxPwdLife: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG krbPwdFailureCountInterval: 2018-02-15T06:43:09Z DEBUG 0 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Kerberos Service Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=cosTemplates,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG cosTemplates 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG cosTemplates 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference: 2018-02-15T06:43:09Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cosTemplate 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG krbContainer 2018-02-15T06:43:09Z DEBUG cosPriority: 2018-02-15T06:43:09Z DEBUG 10000000000 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference: 2018-02-15T06:43:09Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cosTemplate 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG krbContainer 2018-02-15T06:43:09Z DEBUG cosPriority: 2018-02-15T06:43:09Z DEBUG 10000000000 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Default Password Policy,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG ldapsubentry 2018-02-15T06:43:09Z DEBUG cosSuperDefinition 2018-02-15T06:43:09Z DEBUG cosPointerDefinition 2018-02-15T06:43:09Z DEBUG cosAttribute: 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference default 2018-02-15T06:43:09Z DEBUG costemplatedn: 2018-02-15T06:43:09Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG description: 2018-02-15T06:43:09Z DEBUG Default Password Policy for Hosts 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG ldapsubentry 2018-02-15T06:43:09Z DEBUG cosSuperDefinition 2018-02-15T06:43:09Z DEBUG cosPointerDefinition 2018-02-15T06:43:09Z DEBUG cosAttribute: 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference default 2018-02-15T06:43:09Z DEBUG costemplatedn: 2018-02-15T06:43:09Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG description: 2018-02-15T06:43:09Z DEBUG Default Password Policy for Hosts 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=cosTemplates,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG cosTemplates 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG cosTemplates 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference: 2018-02-15T06:43:09Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cosTemplate 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG krbContainer 2018-02-15T06:43:09Z DEBUG cosPriority: 2018-02-15T06:43:09Z DEBUG 10000000000 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference: 2018-02-15T06:43:09Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cosTemplate 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG krbContainer 2018-02-15T06:43:09Z DEBUG cosPriority: 2018-02-15T06:43:09Z DEBUG 10000000000 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Default Password Policy,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG ldapsubentry 2018-02-15T06:43:09Z DEBUG cosSuperDefinition 2018-02-15T06:43:09Z DEBUG cosPointerDefinition 2018-02-15T06:43:09Z DEBUG cosAttribute: 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference default 2018-02-15T06:43:09Z DEBUG costemplatedn: 2018-02-15T06:43:09Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG description: 2018-02-15T06:43:09Z DEBUG Default Password Policy for Services 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG ldapsubentry 2018-02-15T06:43:09Z DEBUG cosSuperDefinition 2018-02-15T06:43:09Z DEBUG cosPointerDefinition 2018-02-15T06:43:09Z DEBUG cosAttribute: 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference default 2018-02-15T06:43:09Z DEBUG costemplatedn: 2018-02-15T06:43:09Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG description: 2018-02-15T06:43:09Z DEBUG Default Password Policy for Services 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=cosTemplates,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=cosTemplates,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG cosTemplates 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=cosTemplates,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsContainer 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG cosTemplates 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Default Password Policy,cn=cosTemplates,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference: 2018-02-15T06:43:09Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cosTemplate 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG krbContainer 2018-02-15T06:43:09Z DEBUG cosPriority: 2018-02-15T06:43:09Z DEBUG 10000000000 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference: 2018-02-15T06:43:09Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG cosTemplate 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG krbContainer 2018-02-15T06:43:09Z DEBUG cosPriority: 2018-02-15T06:43:09Z DEBUG 10000000000 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=Default Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG ldapsubentry 2018-02-15T06:43:09Z DEBUG cosSuperDefinition 2018-02-15T06:43:09Z DEBUG cosPointerDefinition 2018-02-15T06:43:09Z DEBUG cosAttribute: 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference default 2018-02-15T06:43:09Z DEBUG costemplatedn: 2018-02-15T06:43:09Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG description: 2018-02-15T06:43:09Z DEBUG Default Password Policy for Kerberos Services 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=Default Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG ldapsubentry 2018-02-15T06:43:09Z DEBUG cosSuperDefinition 2018-02-15T06:43:09Z DEBUG cosPointerDefinition 2018-02-15T06:43:09Z DEBUG cosAttribute: 2018-02-15T06:43:09Z DEBUG krbPwdPolicyReference default 2018-02-15T06:43:09Z DEBUG costemplatedn: 2018-02-15T06:43:09Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG description: 2018-02-15T06:43:09Z DEBUG Default Password Policy for Kerberos Services 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG Default Password Policy 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-dna.update' 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ipa-winsync 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsSlapdPlugin 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG ipawinsynchomedirattr: 2018-02-15T06:43:09Z DEBUG ipaHomesRootDir 2018-02-15T06:43:09Z DEBUG ipawinsyncnewuserocattr: 2018-02-15T06:43:09Z DEBUG ipauserobjectclasses 2018-02-15T06:43:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:09Z DEBUG libipa_winsync 2018-02-15T06:43:09Z DEBUG ipawinsyncuserflatten: 2018-02-15T06:43:09Z DEBUG true 2018-02-15T06:43:09Z DEBUG ipawinsyncdefaultgroupfilter: 2018-02-15T06:43:09Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2018-02-15T06:43:09Z DEBUG ipawinsyncforcesync: 2018-02-15T06:43:09Z DEBUG true 2018-02-15T06:43:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:09Z DEBUG FreeIPA/1.0 2018-02-15T06:43:09Z DEBUG ipawinsyncrealmattr: 2018-02-15T06:43:09Z DEBUG cn 2018-02-15T06:43:09Z DEBUG ipawinsyncacctdisable: 2018-02-15T06:43:09Z DEBUG both 2018-02-15T06:43:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:09Z DEBUG ipa_winsync_plugin_init 2018-02-15T06:43:09Z DEBUG ipawinsyncnewentryfilter: 2018-02-15T06:43:09Z DEBUG (cn=ipaConfig) 2018-02-15T06:43:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:09Z DEBUG database 2018-02-15T06:43:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:09Z DEBUG FreeIPA project 2018-02-15T06:43:09Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:43:09Z DEBUG 60 2018-02-15T06:43:09Z DEBUG ipawinsyncdefaultgroupattr: 2018-02-15T06:43:09Z DEBUG ipaDefaultPrimaryGroup 2018-02-15T06:43:09Z DEBUG ipawinsyncrealmfilter: 2018-02-15T06:43:09Z DEBUG (objectclass=krbRealmContainer) 2018-02-15T06:43:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:09Z DEBUG preoperation 2018-02-15T06:43:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:09Z DEBUG ipa winsync plugin 2018-02-15T06:43:09Z DEBUG ipawinsyncloginshellattr: 2018-02-15T06:43:09Z DEBUG ipaDefaultLoginShell 2018-02-15T06:43:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:09Z DEBUG ipa-winsync-plugin 2018-02-15T06:43:09Z DEBUG ipawinsyncuserattr: 2018-02-15T06:43:09Z DEBUG uidNumber -1 2018-02-15T06:43:09Z DEBUG gidNumber -1 2018-02-15T06:43:09Z DEBUG remove: 'uidNumber 999' from ipaWinSyncUserAttr, current value [u'uidNumber -1', u'gidNumber -1'] 2018-02-15T06:43:09Z DEBUG remove: 'uidNumber 999' not in ipaWinSyncUserAttr 2018-02-15T06:43:09Z DEBUG remove: 'gidNumber 999' from ipaWinSyncUserAttr, current value [u'uidNumber -1', u'gidNumber -1'] 2018-02-15T06:43:09Z DEBUG remove: 'gidNumber 999' not in ipaWinSyncUserAttr 2018-02-15T06:43:09Z DEBUG add: 'uidNumber -1' to ipaWinSyncUserAttr, current value [u'uidNumber -1', u'gidNumber -1'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'gidNumber -1', u'uidNumber -1'] 2018-02-15T06:43:09Z DEBUG add: 'gidNumber -1' to ipaWinSyncUserAttr, current value [u'gidNumber -1', u'uidNumber -1'] 2018-02-15T06:43:09Z DEBUG add: updated value [u'uidNumber -1', u'gidNumber -1'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ipa-winsync 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsSlapdPlugin 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG ipawinsynchomedirattr: 2018-02-15T06:43:09Z DEBUG ipaHomesRootDir 2018-02-15T06:43:09Z DEBUG ipawinsyncnewuserocattr: 2018-02-15T06:43:09Z DEBUG ipauserobjectclasses 2018-02-15T06:43:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:43:09Z DEBUG libipa_winsync 2018-02-15T06:43:09Z DEBUG ipawinsyncuserflatten: 2018-02-15T06:43:09Z DEBUG true 2018-02-15T06:43:09Z DEBUG ipawinsyncdefaultgroupfilter: 2018-02-15T06:43:09Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2018-02-15T06:43:09Z DEBUG ipawinsyncforcesync: 2018-02-15T06:43:09Z DEBUG true 2018-02-15T06:43:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:43:09Z DEBUG FreeIPA/1.0 2018-02-15T06:43:09Z DEBUG ipawinsyncrealmattr: 2018-02-15T06:43:09Z DEBUG cn 2018-02-15T06:43:09Z DEBUG ipawinsyncacctdisable: 2018-02-15T06:43:09Z DEBUG both 2018-02-15T06:43:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:43:09Z DEBUG ipa_winsync_plugin_init 2018-02-15T06:43:09Z DEBUG ipawinsyncnewentryfilter: 2018-02-15T06:43:09Z DEBUG (cn=ipaConfig) 2018-02-15T06:43:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:43:09Z DEBUG database 2018-02-15T06:43:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:43:09Z DEBUG FreeIPA project 2018-02-15T06:43:09Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:43:09Z DEBUG 60 2018-02-15T06:43:09Z DEBUG ipawinsyncdefaultgroupattr: 2018-02-15T06:43:09Z DEBUG ipaDefaultPrimaryGroup 2018-02-15T06:43:09Z DEBUG ipawinsyncrealmfilter: 2018-02-15T06:43:09Z DEBUG (objectclass=krbRealmContainer) 2018-02-15T06:43:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:43:09Z DEBUG preoperation 2018-02-15T06:43:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:43:09Z DEBUG ipa winsync plugin 2018-02-15T06:43:09Z DEBUG ipawinsyncloginshellattr: 2018-02-15T06:43:09Z DEBUG ipaDefaultLoginShell 2018-02-15T06:43:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:43:09Z DEBUG on 2018-02-15T06:43:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:43:09Z DEBUG ipa-winsync-plugin 2018-02-15T06:43:09Z DEBUG ipawinsyncuserattr: 2018-02-15T06:43:09Z DEBUG uidNumber -1 2018-02-15T06:43:09Z DEBUG gidNumber -1 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-host_nis_groups.update' 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG mepTemplateEntry 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG mepMappedAttr: 2018-02-15T06:43:09Z DEBUG cn: $cn 2018-02-15T06:43:09Z DEBUG memberHost: $dn 2018-02-15T06:43:09Z DEBUG description: ipaNetgroup $cn 2018-02-15T06:43:09Z DEBUG mepStaticAttr: 2018-02-15T06:43:09Z DEBUG ipaUniqueId: autogenerate 2018-02-15T06:43:09Z DEBUG objectclass: ipanisnetgroup 2018-02-15T06:43:09Z DEBUG objectclass: ipaobject 2018-02-15T06:43:09Z DEBUG nisDomainName: pytest.test 2018-02-15T06:43:09Z DEBUG mepRDNAttr: 2018-02-15T06:43:09Z DEBUG cn 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG NGP HGP Template 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG mepTemplateEntry 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG mepMappedAttr: 2018-02-15T06:43:09Z DEBUG cn: $cn 2018-02-15T06:43:09Z DEBUG memberHost: $dn 2018-02-15T06:43:09Z DEBUG description: ipaNetgroup $cn 2018-02-15T06:43:09Z DEBUG mepStaticAttr: 2018-02-15T06:43:09Z DEBUG ipaUniqueId: autogenerate 2018-02-15T06:43:09Z DEBUG objectclass: ipanisnetgroup 2018-02-15T06:43:09Z DEBUG objectclass: ipaobject 2018-02-15T06:43:09Z DEBUG nisDomainName: pytest.test 2018-02-15T06:43:09Z DEBUG mepRDNAttr: 2018-02-15T06:43:09Z DEBUG cn 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG NGP HGP Template 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Updating existing entry: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG NGP Definition 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG managedbase: 2018-02-15T06:43:09Z DEBUG cn=ng,cn=alt,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG originfilter: 2018-02-15T06:43:09Z DEBUG objectclass=ipahostgroup 2018-02-15T06:43:09Z DEBUG originscope: 2018-02-15T06:43:09Z DEBUG cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG managedtemplate: 2018-02-15T06:43:09Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG only: set cn to 'NGP Definition', current value [u'NGP Definition'] 2018-02-15T06:43:09Z DEBUG only: updated value [u'NGP Definition'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG NGP Definition 2018-02-15T06:43:09Z DEBUG objectClass: 2018-02-15T06:43:09Z DEBUG extensibleObject 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG managedbase: 2018-02-15T06:43:09Z DEBUG cn=ng,cn=alt,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG originfilter: 2018-02-15T06:43:09Z DEBUG objectclass=ipahostgroup 2018-02-15T06:43:09Z DEBUG originscope: 2018-02-15T06:43:09Z DEBUG cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG managedtemplate: 2018-02-15T06:43:09Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:43:09Z DEBUG [] 2018-02-15T06:43:09Z DEBUG Updated 0 2018-02-15T06:43:09Z DEBUG Done 2018-02-15T06:43:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-idoverride_index.update' 2018-02-15T06:43:09Z DEBUG New entry: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Initial value 2018-02-15T06:43:09Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG ObjectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsIndex 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ipaOriginalUid 2018-02-15T06:43:09Z DEBUG nsSystemIndex: 2018-02-15T06:43:09Z DEBUG false 2018-02-15T06:43:09Z DEBUG only: set nsIndexType to 'eq', current value [] 2018-02-15T06:43:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:09Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:09Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:09Z DEBUG --------------------------------------------- 2018-02-15T06:43:09Z DEBUG Final value after applying updates 2018-02-15T06:43:09Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:09Z DEBUG ObjectClass: 2018-02-15T06:43:09Z DEBUG top 2018-02-15T06:43:09Z DEBUG nsIndex 2018-02-15T06:43:09Z DEBUG nsIndexType: 2018-02-15T06:43:09Z DEBUG eq 2018-02-15T06:43:09Z DEBUG pres 2018-02-15T06:43:09Z DEBUG cn: 2018-02-15T06:43:09Z DEBUG ipaOriginalUid 2018-02-15T06:43:09Z DEBUG nsSystemIndex: 2018-02-15T06:43:09Z DEBUG false 2018-02-15T06:43:14Z DEBUG Creating task to index attribute: ipaOriginalUid 2018-02-15T06:43:14Z DEBUG Task id: cn=indextask_ipaOriginalUid_137379697942834440_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:43:15Z DEBUG Indexing finished 2018-02-15T06:43:15Z DEBUG New entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:15Z DEBUG --------------------------------------------- 2018-02-15T06:43:15Z DEBUG Initial value 2018-02-15T06:43:15Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:15Z DEBUG ObjectClass: 2018-02-15T06:43:15Z DEBUG top 2018-02-15T06:43:15Z DEBUG nsIndex 2018-02-15T06:43:15Z DEBUG cn: 2018-02-15T06:43:15Z DEBUG ipaAnchorUUID 2018-02-15T06:43:15Z DEBUG nsSystemIndex: 2018-02-15T06:43:15Z DEBUG false 2018-02-15T06:43:15Z DEBUG only: set nsIndexType to 'eq', current value [] 2018-02-15T06:43:15Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:15Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:15Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:15Z DEBUG --------------------------------------------- 2018-02-15T06:43:15Z DEBUG Final value after applying updates 2018-02-15T06:43:15Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:15Z DEBUG ObjectClass: 2018-02-15T06:43:15Z DEBUG top 2018-02-15T06:43:15Z DEBUG nsIndex 2018-02-15T06:43:15Z DEBUG nsIndexType: 2018-02-15T06:43:15Z DEBUG eq 2018-02-15T06:43:15Z DEBUG pres 2018-02-15T06:43:15Z DEBUG cn: 2018-02-15T06:43:15Z DEBUG ipaAnchorUUID 2018-02-15T06:43:15Z DEBUG nsSystemIndex: 2018-02-15T06:43:15Z DEBUG false 2018-02-15T06:43:20Z DEBUG Creating task to index attribute: ipaAnchorUUID 2018-02-15T06:43:20Z DEBUG Task id: cn=indextask_ipaAnchorUUID_137379698003041080_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:43:21Z DEBUG Indexing finished 2018-02-15T06:43:21Z DEBUG Updating existing entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:21Z DEBUG --------------------------------------------- 2018-02-15T06:43:21Z DEBUG Initial value 2018-02-15T06:43:21Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:21Z DEBUG objectClass: 2018-02-15T06:43:21Z DEBUG top 2018-02-15T06:43:21Z DEBUG nsIndex 2018-02-15T06:43:21Z DEBUG nsIndexType: 2018-02-15T06:43:21Z DEBUG eq 2018-02-15T06:43:21Z DEBUG pres 2018-02-15T06:43:21Z DEBUG cn: 2018-02-15T06:43:21Z DEBUG ipaAnchorUUID 2018-02-15T06:43:21Z DEBUG nsSystemIndex: 2018-02-15T06:43:21Z DEBUG false 2018-02-15T06:43:21Z DEBUG remove: 'ipaOriginalUid' from cn, current value [u'ipaAnchorUUID'] 2018-02-15T06:43:21Z DEBUG remove: 'ipaOriginalUid' not in cn 2018-02-15T06:43:21Z DEBUG --------------------------------------------- 2018-02-15T06:43:21Z DEBUG Final value after applying updates 2018-02-15T06:43:21Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:21Z DEBUG objectClass: 2018-02-15T06:43:21Z DEBUG top 2018-02-15T06:43:21Z DEBUG nsIndex 2018-02-15T06:43:21Z DEBUG nsIndexType: 2018-02-15T06:43:21Z DEBUG eq 2018-02-15T06:43:21Z DEBUG pres 2018-02-15T06:43:21Z DEBUG cn: 2018-02-15T06:43:21Z DEBUG ipaAnchorUUID 2018-02-15T06:43:21Z DEBUG nsSystemIndex: 2018-02-15T06:43:21Z DEBUG false 2018-02-15T06:43:21Z DEBUG [] 2018-02-15T06:43:21Z DEBUG Updated 0 2018-02-15T06:43:21Z DEBUG Done 2018-02-15T06:43:21Z DEBUG Parsing update file '/usr/share/ipa/updates/20-indices.update' 2018-02-15T06:43:21Z DEBUG New entry: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:21Z DEBUG --------------------------------------------- 2018-02-15T06:43:21Z DEBUG Initial value 2018-02-15T06:43:21Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:21Z DEBUG ObjectClass: 2018-02-15T06:43:21Z DEBUG top 2018-02-15T06:43:21Z DEBUG nsIndex 2018-02-15T06:43:21Z DEBUG cn: 2018-02-15T06:43:21Z DEBUG memberuid 2018-02-15T06:43:21Z DEBUG nsSystemIndex: 2018-02-15T06:43:21Z DEBUG false 2018-02-15T06:43:21Z DEBUG only: set nsIndexType to 'eq', current value [] 2018-02-15T06:43:21Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:21Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:21Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:21Z DEBUG --------------------------------------------- 2018-02-15T06:43:21Z DEBUG Final value after applying updates 2018-02-15T06:43:21Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:21Z DEBUG ObjectClass: 2018-02-15T06:43:21Z DEBUG top 2018-02-15T06:43:21Z DEBUG nsIndex 2018-02-15T06:43:21Z DEBUG nsIndexType: 2018-02-15T06:43:21Z DEBUG eq 2018-02-15T06:43:21Z DEBUG pres 2018-02-15T06:43:21Z DEBUG cn: 2018-02-15T06:43:21Z DEBUG memberuid 2018-02-15T06:43:21Z DEBUG nsSystemIndex: 2018-02-15T06:43:21Z DEBUG false 2018-02-15T06:43:26Z DEBUG Creating task to index attribute: memberuid 2018-02-15T06:43:26Z DEBUG Task id: cn=indextask_memberuid_137379698063315230_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:43:27Z DEBUG Indexing finished 2018-02-15T06:43:27Z DEBUG Updating existing entry: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:27Z DEBUG --------------------------------------------- 2018-02-15T06:43:27Z DEBUG Initial value 2018-02-15T06:43:27Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:27Z DEBUG nsIndexType: 2018-02-15T06:43:27Z DEBUG eq 2018-02-15T06:43:27Z DEBUG pres 2018-02-15T06:43:27Z DEBUG sub 2018-02-15T06:43:27Z DEBUG objectClass: 2018-02-15T06:43:27Z DEBUG top 2018-02-15T06:43:27Z DEBUG nsIndex 2018-02-15T06:43:27Z DEBUG cn: 2018-02-15T06:43:27Z DEBUG memberHost 2018-02-15T06:43:27Z DEBUG nsSystemIndex: 2018-02-15T06:43:27Z DEBUG false 2018-02-15T06:43:27Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:27Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:27Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:27Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:27Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:27Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:27Z DEBUG --------------------------------------------- 2018-02-15T06:43:27Z DEBUG Final value after applying updates 2018-02-15T06:43:27Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:27Z DEBUG nsIndexType: 2018-02-15T06:43:27Z DEBUG eq 2018-02-15T06:43:27Z DEBUG pres 2018-02-15T06:43:27Z DEBUG sub 2018-02-15T06:43:27Z DEBUG objectClass: 2018-02-15T06:43:27Z DEBUG top 2018-02-15T06:43:27Z DEBUG nsIndex 2018-02-15T06:43:27Z DEBUG cn: 2018-02-15T06:43:27Z DEBUG memberHost 2018-02-15T06:43:27Z DEBUG nsSystemIndex: 2018-02-15T06:43:27Z DEBUG false 2018-02-15T06:43:27Z DEBUG [] 2018-02-15T06:43:27Z DEBUG Updated 0 2018-02-15T06:43:27Z DEBUG Done 2018-02-15T06:43:27Z DEBUG Updating existing entry: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:27Z DEBUG --------------------------------------------- 2018-02-15T06:43:27Z DEBUG Initial value 2018-02-15T06:43:27Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:27Z DEBUG nsIndexType: 2018-02-15T06:43:27Z DEBUG eq 2018-02-15T06:43:27Z DEBUG pres 2018-02-15T06:43:27Z DEBUG sub 2018-02-15T06:43:27Z DEBUG objectClass: 2018-02-15T06:43:27Z DEBUG top 2018-02-15T06:43:27Z DEBUG nsIndex 2018-02-15T06:43:27Z DEBUG cn: 2018-02-15T06:43:27Z DEBUG memberUser 2018-02-15T06:43:27Z DEBUG nsSystemIndex: 2018-02-15T06:43:27Z DEBUG false 2018-02-15T06:43:27Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:27Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:27Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:27Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:27Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:27Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:27Z DEBUG --------------------------------------------- 2018-02-15T06:43:27Z DEBUG Final value after applying updates 2018-02-15T06:43:27Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:27Z DEBUG nsIndexType: 2018-02-15T06:43:27Z DEBUG eq 2018-02-15T06:43:27Z DEBUG pres 2018-02-15T06:43:27Z DEBUG sub 2018-02-15T06:43:27Z DEBUG objectClass: 2018-02-15T06:43:27Z DEBUG top 2018-02-15T06:43:27Z DEBUG nsIndex 2018-02-15T06:43:27Z DEBUG cn: 2018-02-15T06:43:27Z DEBUG memberUser 2018-02-15T06:43:27Z DEBUG nsSystemIndex: 2018-02-15T06:43:27Z DEBUG false 2018-02-15T06:43:27Z DEBUG [] 2018-02-15T06:43:27Z DEBUG Updated 0 2018-02-15T06:43:27Z DEBUG Done 2018-02-15T06:43:27Z DEBUG Updating existing entry: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:27Z DEBUG --------------------------------------------- 2018-02-15T06:43:27Z DEBUG Initial value 2018-02-15T06:43:27Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:27Z DEBUG nsIndexType: 2018-02-15T06:43:27Z DEBUG eq 2018-02-15T06:43:27Z DEBUG objectClass: 2018-02-15T06:43:27Z DEBUG top 2018-02-15T06:43:27Z DEBUG nsIndex 2018-02-15T06:43:27Z DEBUG cn: 2018-02-15T06:43:27Z DEBUG member 2018-02-15T06:43:27Z DEBUG nsSystemIndex: 2018-02-15T06:43:27Z DEBUG false 2018-02-15T06:43:27Z DEBUG only: set nsIndexType to 'eq', current value [u'eq'] 2018-02-15T06:43:27Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:27Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:27Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:27Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:27Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:27Z DEBUG --------------------------------------------- 2018-02-15T06:43:27Z DEBUG Final value after applying updates 2018-02-15T06:43:27Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:27Z DEBUG nsIndexType: 2018-02-15T06:43:27Z DEBUG eq 2018-02-15T06:43:27Z DEBUG pres 2018-02-15T06:43:27Z DEBUG sub 2018-02-15T06:43:27Z DEBUG objectClass: 2018-02-15T06:43:27Z DEBUG top 2018-02-15T06:43:27Z DEBUG nsIndex 2018-02-15T06:43:27Z DEBUG cn: 2018-02-15T06:43:27Z DEBUG member 2018-02-15T06:43:27Z DEBUG nsSystemIndex: 2018-02-15T06:43:27Z DEBUG false 2018-02-15T06:43:27Z DEBUG [(0, u'nsIndexType', [u'pres', u'sub'])] 2018-02-15T06:43:27Z DEBUG Updated 1 2018-02-15T06:43:27Z DEBUG Done 2018-02-15T06:43:32Z DEBUG Creating task to index attribute: member 2018-02-15T06:43:32Z DEBUG Task id: cn=indextask_member_137379698123585590_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:43:33Z DEBUG Indexing finished 2018-02-15T06:43:33Z DEBUG Updating existing entry: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:33Z DEBUG --------------------------------------------- 2018-02-15T06:43:33Z DEBUG Initial value 2018-02-15T06:43:33Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:33Z DEBUG nsIndexType: 2018-02-15T06:43:33Z DEBUG eq 2018-02-15T06:43:33Z DEBUG objectClass: 2018-02-15T06:43:33Z DEBUG top 2018-02-15T06:43:33Z DEBUG nsIndex 2018-02-15T06:43:33Z DEBUG cn: 2018-02-15T06:43:33Z DEBUG uniquemember 2018-02-15T06:43:33Z DEBUG nsSystemIndex: 2018-02-15T06:43:33Z DEBUG false 2018-02-15T06:43:33Z DEBUG only: set nsIndexType to 'eq', current value [u'eq'] 2018-02-15T06:43:33Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:33Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2018-02-15T06:43:33Z DEBUG only: updated value [u'eq', u'sub'] 2018-02-15T06:43:33Z DEBUG --------------------------------------------- 2018-02-15T06:43:33Z DEBUG Final value after applying updates 2018-02-15T06:43:33Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:33Z DEBUG nsIndexType: 2018-02-15T06:43:33Z DEBUG eq 2018-02-15T06:43:33Z DEBUG sub 2018-02-15T06:43:33Z DEBUG objectClass: 2018-02-15T06:43:33Z DEBUG top 2018-02-15T06:43:33Z DEBUG nsIndex 2018-02-15T06:43:33Z DEBUG cn: 2018-02-15T06:43:33Z DEBUG uniquemember 2018-02-15T06:43:33Z DEBUG nsSystemIndex: 2018-02-15T06:43:33Z DEBUG false 2018-02-15T06:43:33Z DEBUG [(0, u'nsIndexType', [u'sub'])] 2018-02-15T06:43:33Z DEBUG Updated 1 2018-02-15T06:43:33Z DEBUG Done 2018-02-15T06:43:38Z DEBUG Creating task to index attribute: uniquemember 2018-02-15T06:43:38Z DEBUG Task id: cn=indextask_uniquemember_137379698183807030_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:43:39Z DEBUG Indexing finished 2018-02-15T06:43:39Z DEBUG Updating existing entry: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:39Z DEBUG --------------------------------------------- 2018-02-15T06:43:39Z DEBUG Initial value 2018-02-15T06:43:39Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:39Z DEBUG nsIndexType: 2018-02-15T06:43:39Z DEBUG eq 2018-02-15T06:43:39Z DEBUG objectClass: 2018-02-15T06:43:39Z DEBUG top 2018-02-15T06:43:39Z DEBUG nsIndex 2018-02-15T06:43:39Z DEBUG cn: 2018-02-15T06:43:39Z DEBUG owner 2018-02-15T06:43:39Z DEBUG nsSystemIndex: 2018-02-15T06:43:39Z DEBUG false 2018-02-15T06:43:39Z DEBUG only: set nsIndexType to 'eq', current value [u'eq'] 2018-02-15T06:43:39Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:39Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2018-02-15T06:43:39Z DEBUG only: updated value [u'eq', u'sub'] 2018-02-15T06:43:39Z DEBUG --------------------------------------------- 2018-02-15T06:43:39Z DEBUG Final value after applying updates 2018-02-15T06:43:39Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:39Z DEBUG nsIndexType: 2018-02-15T06:43:39Z DEBUG eq 2018-02-15T06:43:39Z DEBUG sub 2018-02-15T06:43:39Z DEBUG objectClass: 2018-02-15T06:43:39Z DEBUG top 2018-02-15T06:43:39Z DEBUG nsIndex 2018-02-15T06:43:39Z DEBUG cn: 2018-02-15T06:43:39Z DEBUG owner 2018-02-15T06:43:39Z DEBUG nsSystemIndex: 2018-02-15T06:43:39Z DEBUG false 2018-02-15T06:43:39Z DEBUG [(0, u'nsIndexType', [u'sub'])] 2018-02-15T06:43:39Z DEBUG Updated 1 2018-02-15T06:43:39Z DEBUG Done 2018-02-15T06:43:44Z DEBUG Creating task to index attribute: owner 2018-02-15T06:43:44Z DEBUG Task id: cn=indextask_owner_137379698244030870_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:43:45Z DEBUG Indexing finished 2018-02-15T06:43:45Z DEBUG Updating existing entry: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:45Z DEBUG --------------------------------------------- 2018-02-15T06:43:45Z DEBUG Initial value 2018-02-15T06:43:45Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:45Z DEBUG nsIndexType: 2018-02-15T06:43:45Z DEBUG eq 2018-02-15T06:43:45Z DEBUG pres 2018-02-15T06:43:45Z DEBUG sub 2018-02-15T06:43:45Z DEBUG objectClass: 2018-02-15T06:43:45Z DEBUG top 2018-02-15T06:43:45Z DEBUG nsIndex 2018-02-15T06:43:45Z DEBUG cn: 2018-02-15T06:43:45Z DEBUG manager 2018-02-15T06:43:45Z DEBUG nsSystemIndex: 2018-02-15T06:43:45Z DEBUG false 2018-02-15T06:43:45Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:45Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:45Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:45Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:45Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:45Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:45Z DEBUG --------------------------------------------- 2018-02-15T06:43:45Z DEBUG Final value after applying updates 2018-02-15T06:43:45Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:45Z DEBUG nsIndexType: 2018-02-15T06:43:45Z DEBUG eq 2018-02-15T06:43:45Z DEBUG pres 2018-02-15T06:43:45Z DEBUG sub 2018-02-15T06:43:45Z DEBUG objectClass: 2018-02-15T06:43:45Z DEBUG top 2018-02-15T06:43:45Z DEBUG nsIndex 2018-02-15T06:43:45Z DEBUG cn: 2018-02-15T06:43:45Z DEBUG manager 2018-02-15T06:43:45Z DEBUG nsSystemIndex: 2018-02-15T06:43:45Z DEBUG false 2018-02-15T06:43:45Z DEBUG [] 2018-02-15T06:43:45Z DEBUG Updated 0 2018-02-15T06:43:45Z DEBUG Done 2018-02-15T06:43:45Z DEBUG Updating existing entry: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:45Z DEBUG --------------------------------------------- 2018-02-15T06:43:45Z DEBUG Initial value 2018-02-15T06:43:45Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:45Z DEBUG nsIndexType: 2018-02-15T06:43:45Z DEBUG eq 2018-02-15T06:43:45Z DEBUG pres 2018-02-15T06:43:45Z DEBUG sub 2018-02-15T06:43:45Z DEBUG objectClass: 2018-02-15T06:43:45Z DEBUG top 2018-02-15T06:43:45Z DEBUG nsIndex 2018-02-15T06:43:45Z DEBUG cn: 2018-02-15T06:43:45Z DEBUG secretary 2018-02-15T06:43:45Z DEBUG nsSystemIndex: 2018-02-15T06:43:45Z DEBUG false 2018-02-15T06:43:45Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:45Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:45Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:45Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:45Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:45Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:45Z DEBUG --------------------------------------------- 2018-02-15T06:43:45Z DEBUG Final value after applying updates 2018-02-15T06:43:45Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:45Z DEBUG nsIndexType: 2018-02-15T06:43:45Z DEBUG eq 2018-02-15T06:43:45Z DEBUG pres 2018-02-15T06:43:45Z DEBUG sub 2018-02-15T06:43:45Z DEBUG objectClass: 2018-02-15T06:43:45Z DEBUG top 2018-02-15T06:43:45Z DEBUG nsIndex 2018-02-15T06:43:45Z DEBUG cn: 2018-02-15T06:43:45Z DEBUG secretary 2018-02-15T06:43:45Z DEBUG nsSystemIndex: 2018-02-15T06:43:45Z DEBUG false 2018-02-15T06:43:45Z DEBUG [] 2018-02-15T06:43:45Z DEBUG Updated 0 2018-02-15T06:43:45Z DEBUG Done 2018-02-15T06:43:45Z DEBUG Updating existing entry: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:45Z DEBUG --------------------------------------------- 2018-02-15T06:43:45Z DEBUG Initial value 2018-02-15T06:43:45Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:45Z DEBUG nsIndexType: 2018-02-15T06:43:45Z DEBUG eq 2018-02-15T06:43:45Z DEBUG objectClass: 2018-02-15T06:43:45Z DEBUG top 2018-02-15T06:43:45Z DEBUG nsIndex 2018-02-15T06:43:45Z DEBUG cn: 2018-02-15T06:43:45Z DEBUG seeAlso 2018-02-15T06:43:45Z DEBUG nsSystemIndex: 2018-02-15T06:43:45Z DEBUG false 2018-02-15T06:43:45Z DEBUG only: set nsIndexType to 'eq', current value [u'eq'] 2018-02-15T06:43:45Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:45Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2018-02-15T06:43:45Z DEBUG only: updated value [u'eq', u'sub'] 2018-02-15T06:43:45Z DEBUG --------------------------------------------- 2018-02-15T06:43:45Z DEBUG Final value after applying updates 2018-02-15T06:43:45Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:45Z DEBUG nsIndexType: 2018-02-15T06:43:45Z DEBUG eq 2018-02-15T06:43:45Z DEBUG sub 2018-02-15T06:43:45Z DEBUG objectClass: 2018-02-15T06:43:45Z DEBUG top 2018-02-15T06:43:45Z DEBUG nsIndex 2018-02-15T06:43:45Z DEBUG cn: 2018-02-15T06:43:45Z DEBUG seeAlso 2018-02-15T06:43:45Z DEBUG nsSystemIndex: 2018-02-15T06:43:45Z DEBUG false 2018-02-15T06:43:45Z DEBUG [(0, u'nsIndexType', [u'sub'])] 2018-02-15T06:43:45Z DEBUG Updated 1 2018-02-15T06:43:45Z DEBUG Done 2018-02-15T06:43:50Z DEBUG Creating task to index attribute: seeAlso 2018-02-15T06:43:50Z DEBUG Task id: cn=indextask_seeAlso_137379698304324070_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:43:51Z DEBUG Indexing finished 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG memberOf 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG memberOf 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG fqdn 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG fqdn 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG macAddress 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG macAddress 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG sourcehost 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG sourcehost 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG memberservice 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG memberservice 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG managedby 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG managedby 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG memberallowcmd 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG memberallowcmd 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG memberdenycmd 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG memberdenycmd 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipasudorunas 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipasudorunas 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipasudorunasgroup 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipasudorunasgroup 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG automountkey 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG automountkey 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipakrbprincipalalias 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipakrbprincipalalias 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG Updating existing entry: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipauniqueid 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG objectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipauniqueid 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG [] 2018-02-15T06:43:51Z DEBUG Updated 0 2018-02-15T06:43:51Z DEBUG Done 2018-02-15T06:43:51Z DEBUG New entry: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Initial value 2018-02-15T06:43:51Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG ObjectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipatokenradiusconfiglink 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'eq', current value [] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:51Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:51Z DEBUG --------------------------------------------- 2018-02-15T06:43:51Z DEBUG Final value after applying updates 2018-02-15T06:43:51Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:51Z DEBUG ObjectClass: 2018-02-15T06:43:51Z DEBUG top 2018-02-15T06:43:51Z DEBUG nsIndex 2018-02-15T06:43:51Z DEBUG nsIndexType: 2018-02-15T06:43:51Z DEBUG eq 2018-02-15T06:43:51Z DEBUG pres 2018-02-15T06:43:51Z DEBUG sub 2018-02-15T06:43:51Z DEBUG cn: 2018-02-15T06:43:51Z DEBUG ipatokenradiusconfiglink 2018-02-15T06:43:51Z DEBUG nsSystemIndex: 2018-02-15T06:43:51Z DEBUG false 2018-02-15T06:43:56Z DEBUG Creating task to index attribute: ipatokenradiusconfiglink 2018-02-15T06:43:56Z DEBUG Task id: cn=indextask_ipatokenradiusconfiglink_137379698364920640_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:43:57Z DEBUG Indexing finished 2018-02-15T06:43:57Z DEBUG New entry: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:57Z DEBUG --------------------------------------------- 2018-02-15T06:43:57Z DEBUG Initial value 2018-02-15T06:43:57Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:57Z DEBUG ObjectClass: 2018-02-15T06:43:57Z DEBUG top 2018-02-15T06:43:57Z DEBUG nsIndex 2018-02-15T06:43:57Z DEBUG cn: 2018-02-15T06:43:57Z DEBUG ipaassignedidview 2018-02-15T06:43:57Z DEBUG nsSystemIndex: 2018-02-15T06:43:57Z DEBUG false 2018-02-15T06:43:57Z DEBUG only: set nsIndexType to 'eq', current value [] 2018-02-15T06:43:57Z DEBUG only: updated value [u'eq'] 2018-02-15T06:43:57Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:43:57Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:43:57Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:43:57Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:43:57Z DEBUG --------------------------------------------- 2018-02-15T06:43:57Z DEBUG Final value after applying updates 2018-02-15T06:43:57Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:43:57Z DEBUG ObjectClass: 2018-02-15T06:43:57Z DEBUG top 2018-02-15T06:43:57Z DEBUG nsIndex 2018-02-15T06:43:57Z DEBUG nsIndexType: 2018-02-15T06:43:57Z DEBUG eq 2018-02-15T06:43:57Z DEBUG pres 2018-02-15T06:43:57Z DEBUG sub 2018-02-15T06:43:57Z DEBUG cn: 2018-02-15T06:43:57Z DEBUG ipaassignedidview 2018-02-15T06:43:57Z DEBUG nsSystemIndex: 2018-02-15T06:43:57Z DEBUG false 2018-02-15T06:44:02Z DEBUG Creating task to index attribute: ipaassignedidview 2018-02-15T06:44:02Z DEBUG Task id: cn=indextask_ipaassignedidview_137379698425244590_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:44:03Z DEBUG Indexing finished 2018-02-15T06:44:03Z DEBUG New entry: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:03Z DEBUG --------------------------------------------- 2018-02-15T06:44:03Z DEBUG Initial value 2018-02-15T06:44:03Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:03Z DEBUG ObjectClass: 2018-02-15T06:44:03Z DEBUG top 2018-02-15T06:44:03Z DEBUG nsIndex 2018-02-15T06:44:03Z DEBUG cn: 2018-02-15T06:44:03Z DEBUG ipaallowedtarget 2018-02-15T06:44:03Z DEBUG nsSystemIndex: 2018-02-15T06:44:03Z DEBUG false 2018-02-15T06:44:03Z DEBUG only: set nsIndexType to 'eq', current value [] 2018-02-15T06:44:03Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:03Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:44:03Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:44:03Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:44:03Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:44:03Z DEBUG --------------------------------------------- 2018-02-15T06:44:03Z DEBUG Final value after applying updates 2018-02-15T06:44:03Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:03Z DEBUG ObjectClass: 2018-02-15T06:44:03Z DEBUG top 2018-02-15T06:44:03Z DEBUG nsIndex 2018-02-15T06:44:03Z DEBUG nsIndexType: 2018-02-15T06:44:03Z DEBUG eq 2018-02-15T06:44:03Z DEBUG pres 2018-02-15T06:44:03Z DEBUG sub 2018-02-15T06:44:03Z DEBUG cn: 2018-02-15T06:44:03Z DEBUG ipaallowedtarget 2018-02-15T06:44:03Z DEBUG nsSystemIndex: 2018-02-15T06:44:03Z DEBUG false 2018-02-15T06:44:08Z DEBUG Creating task to index attribute: ipaallowedtarget 2018-02-15T06:44:08Z DEBUG Task id: cn=indextask_ipaallowedtarget_137379698485471240_2888,cn=index,cn=tasks,cn=config 2018-02-15T06:44:09Z DEBUG Indexing finished 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipaMemberCa 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipaMemberCa 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipaMemberCertProfile 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipaMemberCertProfile 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG userCertificate 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsSystemIndex to 'false', current value [u'false'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'false'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG userCertificate 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ntUniqueId 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ntUniqueId 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ntUserDomainId 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ntUserDomainId 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipalocation 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipalocation 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG nsMatchingRule: 2018-02-15T06:44:09Z DEBUG caseIgnoreIA5Match 2018-02-15T06:44:09Z DEBUG caseExactIA5Match 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG krbPrincipalName 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsMatchingRule to 'caseIgnoreIA5Match', current value [u'caseIgnoreIA5Match', u'caseExactIA5Match'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'caseIgnoreIA5Match'] 2018-02-15T06:44:09Z DEBUG only: set nsMatchingRule to 'caseExactIA5Match', current value [u'caseIgnoreIA5Match'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'caseIgnoreIA5Match', u'caseExactIA5Match'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'sub'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG nsMatchingRule: 2018-02-15T06:44:09Z DEBUG caseIgnoreIA5Match 2018-02-15T06:44:09Z DEBUG caseExactIA5Match 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG krbPrincipalName 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG krbCanonicalName 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsSystemIndex to 'false', current value [u'false'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'false'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'sub'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG krbCanonicalName 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG description 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG description 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG l 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG l 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG nsOsVersion 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG nsOsVersion 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG nsHardwarePlatform 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG nsHardwarePlatform 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG nsHostLocation 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG sub 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsindex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG nsHostLocation 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipaservers 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupOfNames 2018-02-15T06:44:09Z DEBUG nestedGroup 2018-02-15T06:44:09Z DEBUG ipaobject 2018-02-15T06:44:09Z DEBUG ipahostgroup 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG fqdn=master.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG fqdn=replica.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG ipaUniqueID: 2018-02-15T06:44:09Z DEBUG c3c83112-1149-11e8-9c96-0050455f413d 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG IPA server hosts 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipaservers 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupOfNames 2018-02-15T06:44:09Z DEBUG nestedGroup 2018-02-15T06:44:09Z DEBUG ipaobject 2018-02-15T06:44:09Z DEBUG ipahostgroup 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG fqdn=master.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG fqdn=replica.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG ipaUniqueID: 2018-02-15T06:44:09Z DEBUG c3c83112-1149-11e8-9c96-0050455f413d 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG IPA server hosts 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipaservers 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupOfNames 2018-02-15T06:44:09Z DEBUG nestedGroup 2018-02-15T06:44:09Z DEBUG ipaobject 2018-02-15T06:44:09Z DEBUG ipahostgroup 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG fqdn=master.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG fqdn=replica.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG ipaUniqueID: 2018-02-15T06:44:09Z DEBUG c3c83112-1149-11e8-9c96-0050455f413d 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG IPA server hosts 2018-02-15T06:44:09Z DEBUG add: 'fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test' to member, current value [u'fqdn=master.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test', u'fqdn=replica.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test', u'fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'fqdn=master.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test', u'fqdn=replica.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test', u'fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipaservers 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupOfNames 2018-02-15T06:44:09Z DEBUG nestedGroup 2018-02-15T06:44:09Z DEBUG ipaobject 2018-02-15T06:44:09Z DEBUG ipahostgroup 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG fqdn=master.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG fqdn=replica.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG ipaUniqueID: 2018-02-15T06:44:09Z DEBUG c3c83112-1149-11e8-9c96-0050455f413d 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG IPA server hosts 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-nss_ldap.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG info: 2018-02-15T06:44:09Z DEBUG IPA V2.0 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG domain 2018-02-15T06:44:09Z DEBUG pilotObject 2018-02-15T06:44:09Z DEBUG domainRelatedObject 2018-02-15T06:44:09Z DEBUG nisDomainObject 2018-02-15T06:44:09Z DEBUG associatedDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG dc: 2018-02-15T06:44:09Z DEBUG pytest 2018-02-15T06:44:09Z DEBUG nisDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG add: 'domain' to objectClass, current value [u'top', u'domain', u'pilotObject', u'domainRelatedObject', u'nisDomainObject'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'top', u'pilotObject', u'domainRelatedObject', u'nisDomainObject', u'domain'] 2018-02-15T06:44:09Z DEBUG add: 'domainRelatedObject' to objectClass, current value [u'top', u'pilotObject', u'domainRelatedObject', u'nisDomainObject', u'domain'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'top', u'pilotObject', u'nisDomainObject', u'domain', u'domainRelatedObject'] 2018-02-15T06:44:09Z DEBUG add: 'nisDomainObject' to objectClass, current value [u'top', u'pilotObject', u'nisDomainObject', u'domain', u'domainRelatedObject'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'top', u'pilotObject', u'domain', u'domainRelatedObject', u'nisDomainObject'] 2018-02-15T06:44:09Z DEBUG add: 'pytest.test' to associatedDomain, current value [u'pytest.test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'pytest.test'] 2018-02-15T06:44:09Z DEBUG add: 'pytest.test' to nisDomain, current value [u'pytest.test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'pytest.test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG info: 2018-02-15T06:44:09Z DEBUG IPA V2.0 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG pilotObject 2018-02-15T06:44:09Z DEBUG domain 2018-02-15T06:44:09Z DEBUG domainRelatedObject 2018-02-15T06:44:09Z DEBUG nisDomainObject 2018-02-15T06:44:09Z DEBUG associatedDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG dc: 2018-02-15T06:44:09Z DEBUG pytest 2018-02-15T06:44:09Z DEBUG nisDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: ou=profile,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: ou=profile,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG organizationalUnit 2018-02-15T06:44:09Z DEBUG ou: 2018-02-15T06:44:09Z DEBUG profiles 2018-02-15T06:44:09Z DEBUG profile 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "attributemap || authenticationmethod || bindtimelimit || cn || createtimestamp || credentiallevel || defaultsearchbase || defaultsearchscope || defaultserverlist || dereferencealiases || entryusn || followreferrals || modifytimestamp || objectclass || objectclassmap || ou || preferredserverlist || profilettl || searchtimelimit || serviceauthenticationmethod || servicecredentiallevel || servicesearchdescriptor")(targetfilter = "(|(objectclass=organizationalUnit)(objectclass=DUAConfigProfile))")(version 3.0;acl "permission:System: Read DUA Profile";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG add: 'top' to objectClass, current value [u'top', u'organizationalUnit'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'organizationalUnit', u'top'] 2018-02-15T06:44:09Z DEBUG add: 'organizationalUnit' to objectClass, current value [u'organizationalUnit', u'top'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'top', u'organizationalUnit'] 2018-02-15T06:44:09Z DEBUG add: 'profiles' to ou, current value [u'profiles', u'profile'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'profile', u'profiles'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: ou=profile,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG organizationalUnit 2018-02-15T06:44:09Z DEBUG ou: 2018-02-15T06:44:09Z DEBUG profile 2018-02-15T06:44:09Z DEBUG profiles 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "attributemap || authenticationmethod || bindtimelimit || cn || createtimestamp || credentiallevel || defaultsearchbase || defaultsearchscope || defaultserverlist || dereferencealiases || entryusn || followreferrals || modifytimestamp || objectclass || objectclassmap || ou || preferredserverlist || profilettl || searchtimelimit || serviceauthenticationmethod || servicecredentiallevel || servicesearchdescriptor")(targetfilter = "(|(objectclass=organizationalUnit)(objectclass=DUAConfigProfile))")(version 3.0;acl "permission:System: Read DUA Profile";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=default,ou=profile,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=default,ou=profile,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG defaultServerList: 2018-02-15T06:44:09Z DEBUG master.pytest.test replica2.pytest.test replica.pytest.test replica3.pytest.test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG default 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG DUAConfigProfile 2018-02-15T06:44:09Z DEBUG serviceSearchDescriptor: 2018-02-15T06:44:09Z DEBUG passwd:cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG group:cn=groups,cn=compat,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG searchTimeLimit: 2018-02-15T06:44:09Z DEBUG 15 2018-02-15T06:44:09Z DEBUG followReferrals: 2018-02-15T06:44:09Z DEBUG TRUE 2018-02-15T06:44:09Z DEBUG objectclassMap: 2018-02-15T06:44:09Z DEBUG shadow:shadowAccount=posixAccount 2018-02-15T06:44:09Z DEBUG bindTimeLimit: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG authenticationMethod: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG defaultSearchBase: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=default,ou=profile,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG defaultServerList: 2018-02-15T06:44:09Z DEBUG master.pytest.test replica2.pytest.test replica.pytest.test replica3.pytest.test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG default 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG DUAConfigProfile 2018-02-15T06:44:09Z DEBUG serviceSearchDescriptor: 2018-02-15T06:44:09Z DEBUG passwd:cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG group:cn=groups,cn=compat,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG searchTimeLimit: 2018-02-15T06:44:09Z DEBUG 15 2018-02-15T06:44:09Z DEBUG followReferrals: 2018-02-15T06:44:09Z DEBUG TRUE 2018-02-15T06:44:09Z DEBUG objectclassMap: 2018-02-15T06:44:09Z DEBUG shadow:shadowAccount=posixAccount 2018-02-15T06:44:09Z DEBUG bindTimeLimit: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG authenticationMethod: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG defaultSearchBase: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-replication.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=replication,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=replication,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsDS5Replica 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsDS5ReplicaRoot: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicachangecount || nsds5replicacleanruv || nsds5replicaid || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicatombstonepurgeinterval || nsds5replicatype || nsds5task || nsstate || objectclass")(targetfilter = "(objectclass=nsds5replica)")(version 3.0;acl "permission:System: Read Replication Information";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG nsDS5ReplicaId: 2018-02-15T06:44:09Z DEBUG 26 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG replication 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=replication,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsDS5Replica 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsDS5ReplicaRoot: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicachangecount || nsds5replicacleanruv || nsds5replicaid || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicatombstonepurgeinterval || nsds5replicatype || nsds5task || nsstate || objectclass")(targetfilter = "(objectclass=nsds5replica)")(version 3.0;acl "permission:System: Read Replication Information";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG nsDS5ReplicaId: 2018-02-15T06:44:09Z DEBUG 26 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG replication 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG krbprincipalname=ldap/master.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG krbprincipalname=ldap/replica.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG krbprincipalname=ldap/replica3.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG replication managers 2018-02-15T06:44:09Z DEBUG add: 'krbprincipalname=ldap/replica3.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test' to member, current value [u'krbprincipalname=ldap/master.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test', u'krbprincipalname=ldap/replica.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test', u'krbprincipalname=ldap/replica3.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'krbprincipalname=ldap/master.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test', u'krbprincipalname=ldap/replica.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test', u'krbprincipalname=ldap/replica3.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG krbprincipalname=ldap/master.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG krbprincipalname=ldap/replica.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG krbprincipalname=ldap/replica3.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG replication managers 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG topology 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG topology 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=domain,cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG domain 2018-02-15T06:44:09Z DEBUG ipaReplTopoConfRoot: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG iparepltopoconf 2018-02-15T06:44:09Z DEBUG nsds5ReplicaStripAttrs: 2018-02-15T06:44:09Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2018-02-15T06:44:09Z DEBUG nsDS5ReplicatedAttributeList: 2018-02-15T06:44:09Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2018-02-15T06:44:09Z DEBUG nsDS5ReplicatedAttributeListTotal: 2018-02-15T06:44:09Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2018-02-15T06:44:09Z DEBUG add: '(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeList, current value [u'(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2018-02-15T06:44:09Z DEBUG add: '(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeListTotal, current value [u'(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2018-02-15T06:44:09Z DEBUG add: 'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp' to nsds5ReplicaStripAttrs, current value [u'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG domain 2018-02-15T06:44:09Z DEBUG ipaReplTopoConfRoot: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG iparepltopoconf 2018-02-15T06:44:09Z DEBUG nsds5ReplicaStripAttrs: 2018-02-15T06:44:09Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2018-02-15T06:44:09Z DEBUG nsDS5ReplicatedAttributeList: 2018-02-15T06:44:09Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2018-02-15T06:44:09Z DEBUG nsDS5ReplicatedAttributeListTotal: 2018-02-15T06:44:09Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Deleting entry cn=realm,cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=realm,cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test did not exist:no such entry 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=replica3.pytest.test,cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=replica3.pytest.test,cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG ipaReplTopoManagedServer 2018-02-15T06:44:09Z DEBUG ipaConfigObject 2018-02-15T06:44:09Z DEBUG ipaSupportedDomainLevelConfig 2018-02-15T06:44:09Z DEBUG ipaMaxDomainLevel: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG ipaMinDomainLevel: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG replica3.pytest.test 2018-02-15T06:44:09Z DEBUG ipaReplTopoManagedSuffix: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'top', u'nsContainer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig', u'ipaReplTopoManagedServer'] 2018-02-15T06:44:09Z DEBUG add: 'dc=pytest,dc=test' to ipaReplTopoManagedSuffix, current value [u'dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=replica3.pytest.test,cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG ipaConfigObject 2018-02-15T06:44:09Z DEBUG ipaSupportedDomainLevelConfig 2018-02-15T06:44:09Z DEBUG ipaReplTopoManagedServer 2018-02-15T06:44:09Z DEBUG ipaMaxDomainLevel: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG ipaMinDomainLevel: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG replica3.pytest.test 2018-02-15T06:44:09Z DEBUG ipaReplTopoManagedSuffix: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=IPA Topology Configuration,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG ipa-topology-plugin 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG IPA Topology Configuration 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG ipa_topo_init 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:44:09Z DEBUG ldbm database 2018-02-15T06:44:09Z DEBUG Multimaster Replication Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG o=ipaca 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.0 2018-02-15T06:44:09Z DEBUG nsslapd-topo-plugin-shared-config-base: 2018-02-15T06:44:09Z DEBUG cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG ipa-topology-plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libtopology 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG object 2018-02-15T06:44:09Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2018-02-15T06:44:09Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-topo-plugin-startup-delay: 2018-02-15T06:44:09Z DEBUG 20 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG freeipa 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG ipa-topology-plugin 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG IPA Topology Configuration 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG ipa_topo_init 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:44:09Z DEBUG ldbm database 2018-02-15T06:44:09Z DEBUG Multimaster Replication Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG o=ipaca 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.0 2018-02-15T06:44:09Z DEBUG nsslapd-topo-plugin-shared-config-base: 2018-02-15T06:44:09Z DEBUG cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG ipa-topology-plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libtopology 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG object 2018-02-15T06:44:09Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2018-02-15T06:44:09Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-topo-plugin-startup-delay: 2018-02-15T06:44:09Z DEBUG 20 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG freeipa 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=changelog5,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=changelog5,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-changelogmaxage: 2018-02-15T06:44:09Z DEBUG 7d 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleobject 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG changelog5 2018-02-15T06:44:09Z DEBUG nsslapd-changelogdir: 2018-02-15T06:44:09Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/cldb 2018-02-15T06:44:09Z DEBUG addifnew: '7d' to nsslapd-changelogmaxage, current value [u'7d'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=changelog5,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-changelogmaxage: 2018-02-15T06:44:09Z DEBUG 7d 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleobject 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG changelog5 2018-02-15T06:44:09Z DEBUG nsslapd-changelogdir: 2018-02-15T06:44:09Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/cldb 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-sslciphers.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=encryption,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=encryption,cn=config 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG encryption 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsEncryptionConfig 2018-02-15T06:44:09Z DEBUG sslVersionMin: 2018-02-15T06:44:09Z DEBUG TLS1.0 2018-02-15T06:44:09Z DEBUG nsSSLSupportedCiphers: 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2018-02-15T06:44:09Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG nsSSLClientAuth: 2018-02-15T06:44:09Z DEBUG allowed 2018-02-15T06:44:09Z DEBUG nsSSLSessionTimeout: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG allowWeakCipher: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG CACertExtractFile: 2018-02-15T06:44:09Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/PYTEST.TEST20IPA20CA.pem 2018-02-15T06:44:09Z DEBUG nsSSL3Ciphers: 2018-02-15T06:44:09Z DEBUG default 2018-02-15T06:44:09Z DEBUG only: set nsSSL3Ciphers to 'default', current value [u'default'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'default'] 2018-02-15T06:44:09Z DEBUG addifnew: 'off' to allowWeakCipher, current value [u'off'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=encryption,cn=config 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG encryption 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsEncryptionConfig 2018-02-15T06:44:09Z DEBUG sslVersionMin: 2018-02-15T06:44:09Z DEBUG TLS1.0 2018-02-15T06:44:09Z DEBUG nsSSLSupportedCiphers: 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2018-02-15T06:44:09Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2018-02-15T06:44:09Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2018-02-15T06:44:09Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2018-02-15T06:44:09Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2018-02-15T06:44:09Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2018-02-15T06:44:09Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2018-02-15T06:44:09Z DEBUG nsSSLClientAuth: 2018-02-15T06:44:09Z DEBUG allowed 2018-02-15T06:44:09Z DEBUG nsSSLSessionTimeout: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG allowWeakCipher: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG CACertExtractFile: 2018-02-15T06:44:09Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/PYTEST.TEST20IPA20CA.pem 2018-02-15T06:44:09Z DEBUG nsSSL3Ciphers: 2018-02-15T06:44:09Z DEBUG default 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-syncrepl.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Retro Changelog Plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Retro Changelog Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:44:09Z DEBUG Class of Service 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libretrocl-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG retrocl_plugin_init 2018-02-15T06:44:09Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:09Z DEBUG 25 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG object 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value [u'off'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'on'] 2018-02-15T06:44:09Z DEBUG add: 'nsuniqueid:targetUniqueId' to nsslapd-attribute, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'nsuniqueid:targetUniqueId'] 2018-02-15T06:44:09Z DEBUG add: '2d' to nsslapd-changelogmaxage, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'2d'] 2018-02-15T06:44:09Z DEBUG add: 'cn=dns,dc=pytest,dc=test' to nsslapd-include-suffix, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'cn=dns,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-attribute: 2018-02-15T06:44:09Z DEBUG nsuniqueid:targetUniqueId 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Retro Changelog Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:44:09Z DEBUG Class of Service 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-changelogmaxage: 2018-02-15T06:44:09Z DEBUG 2d 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libretrocl-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-include-suffix: 2018-02-15T06:44:09Z DEBUG cn=dns,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG retrocl_plugin_init 2018-02-15T06:44:09Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:09Z DEBUG 25 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG object 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG [(2, u'nsslapd-attribute', [u'nsuniqueid:targetUniqueId']), (2, u'nsslapd-pluginEnabled', [u'on']), (2, u'nsslapd-changelogmaxage', [u'2d']), (2, u'nsslapd-include-suffix', [u'cn=dns,dc=pytest,dc=test'])] 2018-02-15T06:44:09Z DEBUG Updated 1 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG memberof 2018-02-15T06:44:09Z DEBUG memberofgroupattr: 2018-02-15T06:44:09Z DEBUG member 2018-02-15T06:44:09Z DEBUG memberUser 2018-02-15T06:44:09Z DEBUG memberHost 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG MemberOf Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG memberof plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libmemberof-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG memberofattr: 2018-02-15T06:44:09Z DEBUG memberOf 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG betxnpostoperation 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG memberof_postop_init 2018-02-15T06:44:09Z DEBUG add: 'dc=pytest,dc=test' to memberofentryscope, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: 'cn=compat,dc=pytest,dc=test' to memberofentryscopeexcludesubtree, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'cn=compat,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: 'cn=provisioning,dc=pytest,dc=test' to memberofentryscopeexcludesubtree, current value [u'cn=compat,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'cn=compat,dc=pytest,dc=test', u'cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test' to memberofentryscopeexcludesubtree, current value [u'cn=compat,dc=pytest,dc=test', u'cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'cn=compat,dc=pytest,dc=test', u'cn=provisioning,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG memberof 2018-02-15T06:44:09Z DEBUG memberofgroupattr: 2018-02-15T06:44:09Z DEBUG member 2018-02-15T06:44:09Z DEBUG memberUser 2018-02-15T06:44:09Z DEBUG memberHost 2018-02-15T06:44:09Z DEBUG memberofentryscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG MemberOf Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG memberof plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libmemberof-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG memberofattr: 2018-02-15T06:44:09Z DEBUG memberOf 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG betxnpostoperation 2018-02-15T06:44:09Z DEBUG memberofentryscopeexcludesubtree: 2018-02-15T06:44:09Z DEBUG cn=compat,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG memberof_postop_init 2018-02-15T06:44:09Z DEBUG [(2, u'memberofentryscope', [u'dc=pytest,dc=test']), (2, u'memberofentryscopeexcludesubtree', [u'cn=compat,dc=pytest,dc=test', u'cn=provisioning,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'])] 2018-02-15T06:44:09Z DEBUG Updated 1 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG referint 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG referential integrity postoperation 2018-02-15T06:44:09Z DEBUG referint-update-delay: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG referential integrity plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libreferint-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:09Z DEBUG 40 2018-02-15T06:44:09Z DEBUG referint-logfile: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/referint 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG betxnpostoperation 2018-02-15T06:44:09Z DEBUG referint-membership-attr: 2018-02-15T06:44:09Z DEBUG member 2018-02-15T06:44:09Z DEBUG uniquemember 2018-02-15T06:44:09Z DEBUG owner 2018-02-15T06:44:09Z DEBUG seeAlso 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG referint_postop_init 2018-02-15T06:44:09Z DEBUG add: 'dc=pytest,dc=test' to nsslapd-plugincontainerscope, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: 'dc=pytest,dc=test' to nsslapd-pluginentryscope, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: 'cn=provisioning,dc=pytest,dc=test' to nsslapd-pluginExcludeEntryScope, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG referint 2018-02-15T06:44:09Z DEBUG nsslapd-plugincontainerscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG referential integrity postoperation 2018-02-15T06:44:09Z DEBUG referint-update-delay: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG referential integrity plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginentryscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-pluginExcludeEntryScope: 2018-02-15T06:44:09Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libreferint-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:09Z DEBUG 40 2018-02-15T06:44:09Z DEBUG referint-logfile: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/referint 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG betxnpostoperation 2018-02-15T06:44:09Z DEBUG referint-membership-attr: 2018-02-15T06:44:09Z DEBUG member 2018-02-15T06:44:09Z DEBUG uniquemember 2018-02-15T06:44:09Z DEBUG owner 2018-02-15T06:44:09Z DEBUG seeAlso 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG referint_postop_init 2018-02-15T06:44:09Z DEBUG [(2, u'nsslapd-plugincontainerscope', [u'dc=pytest,dc=test']), (2, u'nsslapd-pluginExcludeEntryScope', [u'cn=provisioning,dc=pytest,dc=test']), (2, u'nsslapd-pluginentryscope', [u'dc=pytest,dc=test'])] 2018-02-15T06:44:09Z DEBUG Updated 1 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Content Synchronization,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Content Synchronization 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:44:09Z DEBUG Retro Changelog Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libcontentsync-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG sync_init 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG object 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value [u'off'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'on'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Content Synchronization 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-named: 2018-02-15T06:44:09Z DEBUG Retro Changelog Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libcontentsync-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG sync_init 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG object 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG [(2, u'nsslapd-pluginEnabled', [u'on'])] 2018-02-15T06:44:09Z DEBUG Updated 1 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG IPA Unique IDs 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG ipauuidmagicregen: 2018-02-15T06:44:09Z DEBUG autogenerate 2018-02-15T06:44:09Z DEBUG ipauuidfilter: 2018-02-15T06:44:09Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2018-02-15T06:44:09Z DEBUG ipauuidenforce: 2018-02-15T06:44:09Z DEBUG TRUE 2018-02-15T06:44:09Z DEBUG ipauuidscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG ipauuidattr: 2018-02-15T06:44:09Z DEBUG ipaUniqueID 2018-02-15T06:44:09Z DEBUG add: 'cn=provisioning,dc=pytest,dc=test' to ipaUuidExcludeSubtree, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'cn=provisioning,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG IPA Unique IDs 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG ipauuidmagicregen: 2018-02-15T06:44:09Z DEBUG autogenerate 2018-02-15T06:44:09Z DEBUG ipauuidfilter: 2018-02-15T06:44:09Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2018-02-15T06:44:09Z DEBUG ipauuidenforce: 2018-02-15T06:44:09Z DEBUG TRUE 2018-02-15T06:44:09Z DEBUG ipaUuidExcludeSubtree: 2018-02-15T06:44:09Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG ipauuidscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG ipauuidattr: 2018-02-15T06:44:09Z DEBUG ipaUniqueID 2018-02-15T06:44:09Z DEBUG [(2, u'ipaUuidExcludeSubtree', [u'cn=provisioning,dc=pytest,dc=test'])] 2018-02-15T06:44:09Z DEBUG Updated 1 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-user_private_groups.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG mepTemplateEntry 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG mepMappedAttr: 2018-02-15T06:44:09Z DEBUG cn: $uid 2018-02-15T06:44:09Z DEBUG gidNumber: $uidNumber 2018-02-15T06:44:09Z DEBUG description: User private group for $uid 2018-02-15T06:44:09Z DEBUG mepStaticAttr: 2018-02-15T06:44:09Z DEBUG objectclass: posixgroup 2018-02-15T06:44:09Z DEBUG objectclass: ipaobject 2018-02-15T06:44:09Z DEBUG ipaUniqueId: autogenerate 2018-02-15T06:44:09Z DEBUG mepRDNAttr: 2018-02-15T06:44:09Z DEBUG cn 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG UPG Template 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG mepTemplateEntry 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG mepMappedAttr: 2018-02-15T06:44:09Z DEBUG cn: $uid 2018-02-15T06:44:09Z DEBUG gidNumber: $uidNumber 2018-02-15T06:44:09Z DEBUG description: User private group for $uid 2018-02-15T06:44:09Z DEBUG mepStaticAttr: 2018-02-15T06:44:09Z DEBUG objectclass: posixgroup 2018-02-15T06:44:09Z DEBUG objectclass: ipaobject 2018-02-15T06:44:09Z DEBUG ipaUniqueId: autogenerate 2018-02-15T06:44:09Z DEBUG mepRDNAttr: 2018-02-15T06:44:09Z DEBUG cn 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG UPG Template 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG UPG Definition 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG managedbase: 2018-02-15T06:44:09Z DEBUG cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG originfilter: 2018-02-15T06:44:09Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2018-02-15T06:44:09Z DEBUG originscope: 2018-02-15T06:44:09Z DEBUG cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG managedtemplate: 2018-02-15T06:44:09Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG UPG Definition 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG managedbase: 2018-02-15T06:44:09Z DEBUG cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG originfilter: 2018-02-15T06:44:09Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2018-02-15T06:44:09Z DEBUG originscope: 2018-02-15T06:44:09Z DEBUG cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG managedtemplate: 2018-02-15T06:44:09Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG UPG Definition 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG managedbase: 2018-02-15T06:44:09Z DEBUG cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG originfilter: 2018-02-15T06:44:09Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2018-02-15T06:44:09Z DEBUG originscope: 2018-02-15T06:44:09Z DEBUG cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG managedtemplate: 2018-02-15T06:44:09Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG replace: objectclass=posixAccount not found, skipping 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG UPG Definition 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG managedbase: 2018-02-15T06:44:09Z DEBUG cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG originfilter: 2018-02-15T06:44:09Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2018-02-15T06:44:09Z DEBUG originscope: 2018-02-15T06:44:09Z DEBUG cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG managedtemplate: 2018-02-15T06:44:09Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-uuid.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG IPK11 Unique IDs 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG ipauuidmagicregen: 2018-02-15T06:44:09Z DEBUG autogenerate 2018-02-15T06:44:09Z DEBUG ipauuidfilter: 2018-02-15T06:44:09Z DEBUG (objectclass=ipk11Object) 2018-02-15T06:44:09Z DEBUG ipauuidenforce: 2018-02-15T06:44:09Z DEBUG FALSE 2018-02-15T06:44:09Z DEBUG ipauuidscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG ipauuidattr: 2018-02-15T06:44:09Z DEBUG ipk11UniqueID 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG IPK11 Unique IDs 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG ipauuidmagicregen: 2018-02-15T06:44:09Z DEBUG autogenerate 2018-02-15T06:44:09Z DEBUG ipauuidfilter: 2018-02-15T06:44:09Z DEBUG (objectclass=ipk11Object) 2018-02-15T06:44:09Z DEBUG ipauuidenforce: 2018-02-15T06:44:09Z DEBUG FALSE 2018-02-15T06:44:09Z DEBUG ipauuidscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG ipauuidattr: 2018-02-15T06:44:09Z DEBUG ipk11UniqueID 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-whoami.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG whoami-plugin 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG whoami 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG whoami extended operation plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libwhoami-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG extendedop 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG whoami_init 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG whoami-plugin 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG whoami 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG whoami extended operation plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libwhoami-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG extendedop 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG whoami_init 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/20-winsync_index.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ntUniqueId 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ntUniqueId 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ntUserDomainId 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2018-02-15T06:44:09Z DEBUG only: updated value [u'eq', u'pres'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsIndexType: 2018-02-15T06:44:09Z DEBUG eq 2018-02-15T06:44:09Z DEBUG pres 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsIndex 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ntUserDomainId 2018-02-15T06:44:09Z DEBUG nsSystemIndex: 2018-02-15T06:44:09Z DEBUG false 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/21-ca_renewal_container.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Add CA Certificate For Renewal";allow (add) groupdn = "ldap:///cn=System: Add CA Certificate For Renewal,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "usercertificate")(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Modify CA Certificate For Renewal";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate For Renewal,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Read CA Renewal Information";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ca_renewal 2018-02-15T06:44:09Z DEBUG add: 'top' to objectClass, current value [u'nsContainer', u'top'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'nsContainer', u'top'] 2018-02-15T06:44:09Z DEBUG add: 'nsContainer' to objectClass, current value [u'nsContainer', u'top'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'top', u'nsContainer'] 2018-02-15T06:44:09Z DEBUG add: 'ca_renewal' to cn, current value [u'ca_renewal'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'ca_renewal'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Add CA Certificate For Renewal";allow (add) groupdn = "ldap:///cn=System: Add CA Certificate For Renewal,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "usercertificate")(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Modify CA Certificate For Renewal";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate For Renewal,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Read CA Renewal Information";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ca_renewal 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/21-certstore_container.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG certificates 2018-02-15T06:44:09Z DEBUG add: 'top' to objectClass, current value [u'nsContainer', u'top'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'nsContainer', u'top'] 2018-02-15T06:44:09Z DEBUG add: 'nsContainer' to objectClass, current value [u'nsContainer', u'top'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'top', u'nsContainer'] 2018-02-15T06:44:09Z DEBUG add: 'certificates' to cn, current value [u'certificates'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'certificates'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG certificates 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/21-replicas_container.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG replicas 2018-02-15T06:44:09Z DEBUG add: 'top' to objectClass, current value [u'nsContainer', u'top'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'nsContainer', u'top'] 2018-02-15T06:44:09Z DEBUG add: 'nsContainer' to objectClass, current value [u'nsContainer', u'top'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'top', u'nsContainer'] 2018-02-15T06:44:09Z DEBUG add: 'replicas' to cn, current value [u'replicas'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'replicas'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG replicas 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/25-referint.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG referint 2018-02-15T06:44:09Z DEBUG nsslapd-pluginentryscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG referential integrity postoperation 2018-02-15T06:44:09Z DEBUG referint-update-delay: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-pluginexcludeentryscope: 2018-02-15T06:44:09Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG referential integrity plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libreferint-plugin 2018-02-15T06:44:09Z DEBUG nsslapd-plugincontainerscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:09Z DEBUG 40 2018-02-15T06:44:09Z DEBUG referint-logfile: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/referint 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG betxnpostoperation 2018-02-15T06:44:09Z DEBUG referint-membership-attr: 2018-02-15T06:44:09Z DEBUG member 2018-02-15T06:44:09Z DEBUG uniquemember 2018-02-15T06:44:09Z DEBUG owner 2018-02-15T06:44:09Z DEBUG seeAlso 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG referint_postop_init 2018-02-15T06:44:09Z DEBUG add: 'manager' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager'] 2018-02-15T06:44:09Z DEBUG add: 'secretary' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary'] 2018-02-15T06:44:09Z DEBUG add: 'memberuser' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser'] 2018-02-15T06:44:09Z DEBUG add: 'memberhost' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost'] 2018-02-15T06:44:09Z DEBUG add: 'sourcehost' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost'] 2018-02-15T06:44:09Z DEBUG add: 'memberservice' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice'] 2018-02-15T06:44:09Z DEBUG add: 'managedby' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby'] 2018-02-15T06:44:09Z DEBUG add: 'memberallowcmd' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd'] 2018-02-15T06:44:09Z DEBUG add: 'memberdenycmd' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd'] 2018-02-15T06:44:09Z DEBUG add: 'ipasudorunas' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas'] 2018-02-15T06:44:09Z DEBUG add: 'ipasudorunasgroup' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup'] 2018-02-15T06:44:09Z DEBUG add: 'ipatokenradiusconfiglink' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink'] 2018-02-15T06:44:09Z DEBUG add: 'ipaassignedidview' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview'] 2018-02-15T06:44:09Z DEBUG add: 'ipaallowedtarget' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget'] 2018-02-15T06:44:09Z DEBUG add: 'ipamemberca' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca'] 2018-02-15T06:44:09Z DEBUG add: 'ipamembercertprofile' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile'] 2018-02-15T06:44:09Z DEBUG add: 'ipalocation' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG referint 2018-02-15T06:44:09Z DEBUG nsslapd-pluginentryscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG referential integrity postoperation 2018-02-15T06:44:09Z DEBUG referint-update-delay: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-pluginexcludeentryscope: 2018-02-15T06:44:09Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG referential integrity plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libreferint-plugin 2018-02-15T06:44:09Z DEBUG nsslapd-plugincontainerscope: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:09Z DEBUG 40 2018-02-15T06:44:09Z DEBUG referint-logfile: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/referint 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG betxnpostoperation 2018-02-15T06:44:09Z DEBUG referint-membership-attr: 2018-02-15T06:44:09Z DEBUG member 2018-02-15T06:44:09Z DEBUG uniquemember 2018-02-15T06:44:09Z DEBUG owner 2018-02-15T06:44:09Z DEBUG seeAlso 2018-02-15T06:44:09Z DEBUG manager 2018-02-15T06:44:09Z DEBUG secretary 2018-02-15T06:44:09Z DEBUG memberuser 2018-02-15T06:44:09Z DEBUG memberhost 2018-02-15T06:44:09Z DEBUG sourcehost 2018-02-15T06:44:09Z DEBUG memberservice 2018-02-15T06:44:09Z DEBUG managedby 2018-02-15T06:44:09Z DEBUG memberallowcmd 2018-02-15T06:44:09Z DEBUG memberdenycmd 2018-02-15T06:44:09Z DEBUG ipasudorunas 2018-02-15T06:44:09Z DEBUG ipasudorunasgroup 2018-02-15T06:44:09Z DEBUG ipatokenradiusconfiglink 2018-02-15T06:44:09Z DEBUG ipaassignedidview 2018-02-15T06:44:09Z DEBUG ipaallowedtarget 2018-02-15T06:44:09Z DEBUG ipamemberca 2018-02-15T06:44:09Z DEBUG ipamembercertprofile 2018-02-15T06:44:09Z DEBUG ipalocation 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG referint_postop_init 2018-02-15T06:44:09Z DEBUG [(0, u'referint-membership-attr', [u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation'])] 2018-02-15T06:44:09Z DEBUG Updated 1 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/30-provisioning.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG provisioning 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG provisioning 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG accounts 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG accounts 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG staged users 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG staged users 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG deleted users 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG deleted users 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG staged users 2018-02-15T06:44:09Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG staged users 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG deleted users 2018-02-15T06:44:09Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG add: '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)' to aci, current value [u'(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG deleted users 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cosSuperDefinition 2018-02-15T06:44:09Z DEBUG cosPointerDefinition 2018-02-15T06:44:09Z DEBUG ldapSubEntry 2018-02-15T06:44:09Z DEBUG costemplatedn: 2018-02-15T06:44:09Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG provisioning accounts lock 2018-02-15T06:44:09Z DEBUG cosAttribute: 2018-02-15T06:44:09Z DEBUG nsaccountlock operational 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cosSuperDefinition 2018-02-15T06:44:09Z DEBUG cosPointerDefinition 2018-02-15T06:44:09Z DEBUG ldapSubEntry 2018-02-15T06:44:09Z DEBUG costemplatedn: 2018-02-15T06:44:09Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG provisioning accounts lock 2018-02-15T06:44:09Z DEBUG cosAttribute: 2018-02-15T06:44:09Z DEBUG nsaccountlock operational 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG cosTemplate 2018-02-15T06:44:09Z DEBUG cosPriority: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Inactivation cos template 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG cosTemplate 2018-02-15T06:44:09Z DEBUG cosPriority: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Inactivation cos template 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/30-s4u2proxy.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Add Service Delegations";allow (add) groupdn = "ldap:///cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaallowedtarget || memberprincipal")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Modify Service Delegation Membership";allow (write) groupdn = "ldap:///cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaallowedtarget || memberprincipal || modifytimestamp || objectclass")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Read Service Delegations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Remove Service Delegations";allow (delete) groupdn = "ldap:///cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG s4u2proxy 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Add Service Delegations";allow (add) groupdn = "ldap:///cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaallowedtarget || memberprincipal")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Modify Service Delegation Membership";allow (write) groupdn = "ldap:///cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaallowedtarget || memberprincipal || modifytimestamp || objectclass")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Read Service Delegations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Remove Service Delegations";allow (delete) groupdn = "ldap:///cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG s4u2proxy 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG ipaKrb5DelegationACL 2018-02-15T06:44:09Z DEBUG groupOfPrincipals 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG ipaAllowedTarget: 2018-02-15T06:44:09Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberPrincipal: 2018-02-15T06:44:09Z DEBUG HTTP/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG HTTP/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG HTTP/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa-http-delegation 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG ipaKrb5DelegationACL 2018-02-15T06:44:09Z DEBUG groupOfPrincipals 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG ipaAllowedTarget: 2018-02-15T06:44:09Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberPrincipal: 2018-02-15T06:44:09Z DEBUG HTTP/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG HTTP/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG HTTP/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa-http-delegation 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG groupOfPrincipals 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG memberPrincipal: 2018-02-15T06:44:09Z DEBUG ldap/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG ldap/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG ldap/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa-ldap-delegation-targets 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG groupOfPrincipals 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG memberPrincipal: 2018-02-15T06:44:09Z DEBUG ldap/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG ldap/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG ldap/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa-ldap-delegation-targets 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG ipaKrb5DelegationACL 2018-02-15T06:44:09Z DEBUG groupOfPrincipals 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG ipaAllowedTarget: 2018-02-15T06:44:09Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberPrincipal: 2018-02-15T06:44:09Z DEBUG HTTP/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG HTTP/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG HTTP/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa-http-delegation 2018-02-15T06:44:09Z DEBUG add: 'HTTP/replica3.pytest.test@PYTEST.TEST' to memberPrincipal, current value [u'HTTP/master.pytest.test@PYTEST.TEST', u'HTTP/replica.pytest.test@PYTEST.TEST', u'HTTP/replica3.pytest.test@PYTEST.TEST'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'HTTP/master.pytest.test@PYTEST.TEST', u'HTTP/replica.pytest.test@PYTEST.TEST', u'HTTP/replica3.pytest.test@PYTEST.TEST'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG ipaKrb5DelegationACL 2018-02-15T06:44:09Z DEBUG groupOfPrincipals 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG ipaAllowedTarget: 2018-02-15T06:44:09Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberPrincipal: 2018-02-15T06:44:09Z DEBUG HTTP/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG HTTP/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG HTTP/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa-http-delegation 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG groupOfPrincipals 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG memberPrincipal: 2018-02-15T06:44:09Z DEBUG ldap/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG ldap/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG ldap/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa-ldap-delegation-targets 2018-02-15T06:44:09Z DEBUG add: 'ldap/replica3.pytest.test@PYTEST.TEST' to memberPrincipal, current value [u'ldap/master.pytest.test@PYTEST.TEST', u'ldap/replica.pytest.test@PYTEST.TEST', u'ldap/replica3.pytest.test@PYTEST.TEST'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'ldap/master.pytest.test@PYTEST.TEST', u'ldap/replica.pytest.test@PYTEST.TEST', u'ldap/replica3.pytest.test@PYTEST.TEST'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG groupOfPrincipals 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG memberPrincipal: 2018-02-15T06:44:09Z DEBUG ldap/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG ldap/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG ldap/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa-ldap-delegation-targets 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/37-locations.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=locations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=locations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Add IPA Locations";allow (add) groupdn = "ldap:///cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "description")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Modify IPA Locations";allow (write) groupdn = "ldap:///cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || description || entryusn || idnsname || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Read IPA Locations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Remove IPA Locations";allow (delete) groupdn = "ldap:///cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG locations 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=locations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Add IPA Locations";allow (add) groupdn = "ldap:///cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "description")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Modify IPA Locations";allow (write) groupdn = "ldap:///cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || description || entryusn || idnsname || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Read IPA Locations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Remove IPA Locations";allow (delete) groupdn = "ldap:///cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG locations 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/40-automember.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG Auto Membership 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Auto Membership Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG Auto Membership plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libautomember-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG nsslapd-pluginConfigArea: 2018-02-15T06:44:09Z DEBUG cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG betxnpreoperation 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG automember_init 2018-02-15T06:44:09Z DEBUG addifnew: 'cn=automember,cn=etc,dc=pytest,dc=test' to nsslapd-pluginConfigArea, current value [u'cn=automember,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:09Z DEBUG Auto Membership 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Auto Membership Plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:09Z DEBUG 1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:09Z DEBUG Auto Membership plugin 2018-02-15T06:44:09Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:09Z DEBUG libautomember-plugin 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsSlapdPlugin 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:09Z DEBUG database 2018-02-15T06:44:09Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:09Z DEBUG 389 Project 2018-02-15T06:44:09Z DEBUG nsslapd-pluginConfigArea: 2018-02-15T06:44:09Z DEBUG cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:09Z DEBUG betxnpreoperation 2018-02-15T06:44:09Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:09Z DEBUG automember_init 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "automemberdefaultgroup || automemberdisabled || automemberfilter || automembergroupingattr || automemberscope || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberdefinition)")(version 3.0;acl "permission:System: Read Automember Definitions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "automemberexclusiveregex || automemberinclusiveregex || automembertargetgroup || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberregexrule)")(version 3.0;acl "permission:System: Read Automember Rules";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG automember 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "automemberdefaultgroup || automemberdisabled || automemberfilter || automembergroupingattr || automemberscope || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberdefinition)")(version 3.0;acl "permission:System: Read Automember Definitions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "automemberexclusiveregex || automemberinclusiveregex || automembertargetgroup || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberregexrule)")(version 3.0;acl "permission:System: Read Automember Rules";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG automember 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Hostgroup,cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG autoMemberDefinition 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG autoMemberGroupingAttr: 2018-02-15T06:44:09Z DEBUG member:dn 2018-02-15T06:44:09Z DEBUG autoMemberFilter: 2018-02-15T06:44:09Z DEBUG objectclass=ipaHost 2018-02-15T06:44:09Z DEBUG autoMemberScope: 2018-02-15T06:44:09Z DEBUG cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Hostgroup 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG autoMemberDefinition 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG autoMemberGroupingAttr: 2018-02-15T06:44:09Z DEBUG member:dn 2018-02-15T06:44:09Z DEBUG autoMemberFilter: 2018-02-15T06:44:09Z DEBUG objectclass=ipaHost 2018-02-15T06:44:09Z DEBUG autoMemberScope: 2018-02-15T06:44:09Z DEBUG cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Hostgroup 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Group,cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG autoMemberDefinition 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG autoMemberGroupingAttr: 2018-02-15T06:44:09Z DEBUG member:dn 2018-02-15T06:44:09Z DEBUG autoMemberFilter: 2018-02-15T06:44:09Z DEBUG objectclass=posixAccount 2018-02-15T06:44:09Z DEBUG autoMemberScope: 2018-02-15T06:44:09Z DEBUG cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Group 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG autoMemberDefinition 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG autoMemberGroupingAttr: 2018-02-15T06:44:09Z DEBUG member:dn 2018-02-15T06:44:09Z DEBUG autoMemberFilter: 2018-02-15T06:44:09Z DEBUG objectclass=posixAccount 2018-02-15T06:44:09Z DEBUG autoMemberScope: 2018-02-15T06:44:09Z DEBUG cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Group 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/40-certprofile.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ca,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ca,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ca 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ca,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ca 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=certprofiles,cn=ca,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=certprofiles,cn=ca,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Delete Certificate Profile";allow (delete) groupdn = "ldap:///cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Import Certificate Profile";allow (add) groupdn = "ldap:///cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || ipacertprofilestoreissued")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Modify Certificate Profile";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacertprofilestoreissued || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Read Certificate Profiles";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG certprofiles 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=certprofiles,cn=ca,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Delete Certificate Profile";allow (delete) groupdn = "ldap:///cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Import Certificate Profile";allow (add) groupdn = "ldap:///cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || ipacertprofilestoreissued")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Modify Certificate Profile";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacertprofilestoreissued || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Read Certificate Profiles";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG certprofiles 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Parsing update file '/usr/share/ipa/updates/40-delegation.update' 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Write IPA Configuration 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Write IPA Configuration 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Write IPA Configuration 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Write IPA Configuration 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG ipapermission 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Write IPA Configuration 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG ipapermission 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Write IPA Configuration 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG info: 2018-02-15T06:44:09Z DEBUG IPA V2.0 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG domain 2018-02-15T06:44:09Z DEBUG pilotObject 2018-02-15T06:44:09Z DEBUG domainRelatedObject 2018-02-15T06:44:09Z DEBUG nisDomainObject 2018-02-15T06:44:09Z DEBUG associatedDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG dc: 2018-02-15T06:44:09Z DEBUG pytest 2018-02-15T06:44:09Z DEBUG nisDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG add: '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG info: 2018-02-15T06:44:09Z DEBUG IPA V2.0 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG domain 2018-02-15T06:44:09Z DEBUG pilotObject 2018-02-15T06:44:09Z DEBUG domainRelatedObject 2018-02-15T06:44:09Z DEBUG nisDomainObject 2018-02-15T06:44:09Z DEBUG associatedDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG dc: 2018-02-15T06:44:09Z DEBUG pytest 2018-02-15T06:44:09Z DEBUG nisDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG HBAC Administrator 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG HBAC Administrator 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG HBAC Administrator 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG HBAC Administrator 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Sudo Administrator 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Sudo Administrator 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Sudo Administrator 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Sudo Administrator 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Password Policy Administrator 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Password Policy Administrator 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Password Policy Administrator 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Password Policy Administrator 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Host Enrollment 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Host Enrollment 2018-02-15T06:44:09Z DEBUG add: 'cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Host Enrollment 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Host Enrollment 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG info: 2018-02-15T06:44:09Z DEBUG IPA V2.0 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG domain 2018-02-15T06:44:09Z DEBUG pilotObject 2018-02-15T06:44:09Z DEBUG domainRelatedObject 2018-02-15T06:44:09Z DEBUG nisDomainObject 2018-02-15T06:44:09Z DEBUG associatedDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG dc: 2018-02-15T06:44:09Z DEBUG pytest 2018-02-15T06:44:09Z DEBUG nisDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:09Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:09Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG info: 2018-02-15T06:44:09Z DEBUG IPA V2.0 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG domain 2018-02-15T06:44:09Z DEBUG pilotObject 2018-02-15T06:44:09Z DEBUG domainRelatedObject 2018-02-15T06:44:09Z DEBUG nisDomainObject 2018-02-15T06:44:09Z DEBUG associatedDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG dc: 2018-02-15T06:44:09Z DEBUG pytest 2018-02-15T06:44:09Z DEBUG nisDomain: 2018-02-15T06:44:09Z DEBUG pytest.test 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG SELinux User Map Administrators 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG SELinux User Map Administrators 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG SELinux User Map Administrators 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG SELinux User Map Administrators 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:09Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG ipapermission 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Retrieve Certificates from the CA 2018-02-15T06:44:09Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test' to member, current value [u'cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test', u'cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test', u'cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG ipapermission 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Retrieve Certificates from the CA 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG ipapermission 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Revoke Certificate 2018-02-15T06:44:09Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test' to member, current value [u'cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test', u'cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test', u'cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG ipapermission 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Revoke Certificate 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:09Z DEBUG add: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG ipa 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG certificates 2018-02-15T06:44:09Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:09Z DEBUG add: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nsContainer 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG certificates 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Automember Task Administrator 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Automember Task Administrator 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG nestedgroup 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG memberOf: 2018-02-15T06:44:09Z DEBUG cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG description: 2018-02-15T06:44:09Z DEBUG Automember Task Administrator 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Automember Task Administrator 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG ipapermission 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG ipaPermissionType: 2018-02-15T06:44:09Z DEBUG SYSTEM 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Add Automember Rebuild Membership Task 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG member: 2018-02-15T06:44:09Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG groupofnames 2018-02-15T06:44:09Z DEBUG ipapermission 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG ipaPermissionType: 2018-02-15T06:44:09Z DEBUG SYSTEM 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG Add Automember Rebuild Membership Task 2018-02-15T06:44:09Z DEBUG [] 2018-02-15T06:44:09Z DEBUG Updated 0 2018-02-15T06:44:09Z DEBUG Done 2018-02-15T06:44:09Z DEBUG Updating existing entry: cn=config 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Initial value 2018-02-15T06:44:09Z DEBUG dn: cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-betype: 2018-02-15T06:44:09Z DEBUG ldbm database 2018-02-15T06:44:09Z DEBUG nsslapd-nagle: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:09Z DEBUG 64 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:09Z DEBUG 500 2018-02-15T06:44:09Z DEBUG passwordMinAlphas: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-readonly: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:09Z DEBUG allowed 2018-02-15T06:44:09Z DEBUG passwordMinUppers: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-plugin: 2018-02-15T06:44:09Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:09Z DEBUG 2097152 2018-02-15T06:44:09Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:09Z DEBUG 20971520 2018-02-15T06:44:09Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:09Z DEBUG 3600 2018-02-15T06:44:09Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:09Z DEBUG 3 2018-02-15T06:44:09Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:09Z DEBUG -10 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:09Z DEBUG week 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG passwordMinAge: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:09Z DEBUG week 2018-02-15T06:44:09Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:09Z DEBUG 60 2018-02-15T06:44:09Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:09Z DEBUG 8192 2018-02-15T06:44:09Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordInHistory: 2018-02-15T06:44:09Z DEBUG 6 2018-02-15T06:44:09Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:09Z DEBUG 8192 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:09Z DEBUG month 2018-02-15T06:44:09Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG passwordMaxAge: 2018-02-15T06:44:09Z DEBUG 8640000 2018-02-15T06:44:09Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:09Z DEBUG gidNumber 2018-02-15T06:44:09Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:09Z DEBUG day 2018-02-15T06:44:09Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:09Z DEBUG /tmp 2018-02-15T06:44:09Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:09Z DEBUG 600 2018-02-15T06:44:09Z DEBUG nsslapd-counters: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:09Z DEBUG month 2018-02-15T06:44:09Z DEBUG nsslapd-minssf: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:09Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:09Z DEBUG nsslapd-localuser: 2018-02-15T06:44:09Z DEBUG dirsrv 2018-02-15T06:44:09Z DEBUG nsslapd-security: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordChange: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:09Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:09Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:09Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:09Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:09Z DEBUG passwordMaxFailure: 2018-02-15T06:44:09Z DEBUG 3 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:09Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:09Z DEBUG 128 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:09Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:09Z DEBUG cn=Directory Manager 2018-02-15T06:44:09Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:09Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:09Z DEBUG 600 2018-02-15T06:44:09Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:09Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG passwordMustChange: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordExp: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:09Z DEBUG dirsrv-log 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:09Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:09Z DEBUG cn=Directory Manager 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordMinLength: 2018-02-15T06:44:09Z DEBUG 8 2018-02-15T06:44:09Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:09Z DEBUG -10 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:09Z DEBUG week 2018-02-15T06:44:09Z DEBUG nsslapd-securePort: 2018-02-15T06:44:09Z DEBUG 636 2018-02-15T06:44:09Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG config 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapdConfig 2018-02-15T06:44:09Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:09Z DEBUG next 2018-02-15T06:44:09Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:09Z DEBUG -10 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:09Z DEBUG 600 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordGraceLimit: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG passwordWarning: 2018-02-15T06:44:09Z DEBUG 86400 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:09Z DEBUG 600 2018-02-15T06:44:09Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:09Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:09Z DEBUG nsslapd-config: 2018-02-15T06:44:09Z DEBUG cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:09Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:09Z DEBUG 256 2018-02-15T06:44:09Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:09Z DEBUG 2097152 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:09Z DEBUG month 2018-02-15T06:44:09Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:09Z DEBUG SSHA512 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG passwordLockout: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:09Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:09Z DEBUG nsslapd-certdir: 2018-02-15T06:44:09Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:09Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:09Z DEBUG 10 2018-02-15T06:44:09Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:09Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:09Z DEBUG 16 2018-02-15T06:44:09Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-localhost: 2018-02-15T06:44:09Z DEBUG replica3.pytest.test 2018-02-15T06:44:09Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:09Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:09Z DEBUG passwordMin8bit: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:09Z DEBUG uidNumber 2018-02-15T06:44:09Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:09Z DEBUG warn 2018-02-15T06:44:09Z DEBUG passwordMinCategories: 2018-02-15T06:44:09Z DEBUG 3 2018-02-15T06:44:09Z DEBUG passwordMinLowers: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordAdminDN: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordMinSpecials: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:09Z DEBUG 40 2018-02-15T06:44:09Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:09Z DEBUG -1 2018-02-15T06:44:09Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:09Z DEBUG none 2018-02-15T06:44:09Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:09Z DEBUG month 2018-02-15T06:44:09Z DEBUG passwordUnlock: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:09Z DEBUG 2097152 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:09Z DEBUG dc=example,dc=com 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-localssf: 2018-02-15T06:44:09Z DEBUG 71 2018-02-15T06:44:09Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:09Z DEBUG 2000 2018-02-15T06:44:09Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:09Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:09Z DEBUG 2097152 2018-02-15T06:44:09Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:09Z DEBUG 3600 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-port: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:09Z DEBUG cn=schema 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG cn=monitor 2018-02-15T06:44:09Z DEBUG cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:09Z DEBUG 600 2018-02-15T06:44:09Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:09Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:09Z DEBUG 300000 2018-02-15T06:44:09Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-rundir: 2018-02-15T06:44:09Z DEBUG /var/run/dirsrv 2018-02-15T06:44:09Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:09Z DEBUG replication-only 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:09Z DEBUG 16384 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:09Z DEBUG 10000 2018-02-15T06:44:09Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordMinDigits: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG passwordStorageScheme: 2018-02-15T06:44:09Z DEBUG SSHA512 2018-02-15T06:44:09Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG add: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [] 2018-02-15T06:44:09Z DEBUG add: updated value [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:09Z DEBUG --------------------------------------------- 2018-02-15T06:44:09Z DEBUG Final value after applying updates 2018-02-15T06:44:09Z DEBUG dn: cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-betype: 2018-02-15T06:44:09Z DEBUG ldbm database 2018-02-15T06:44:09Z DEBUG nsslapd-nagle: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:09Z DEBUG 64 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:09Z DEBUG 500 2018-02-15T06:44:09Z DEBUG passwordMinAlphas: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-readonly: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:09Z DEBUG allowed 2018-02-15T06:44:09Z DEBUG passwordMinUppers: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-plugin: 2018-02-15T06:44:09Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:09Z DEBUG 2097152 2018-02-15T06:44:09Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:09Z DEBUG 20971520 2018-02-15T06:44:09Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:09Z DEBUG 3600 2018-02-15T06:44:09Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:09Z DEBUG 3 2018-02-15T06:44:09Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:09Z DEBUG -10 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:09Z DEBUG week 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG passwordMinAge: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:09Z DEBUG week 2018-02-15T06:44:09Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:09Z DEBUG 60 2018-02-15T06:44:09Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:09Z DEBUG 8192 2018-02-15T06:44:09Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordInHistory: 2018-02-15T06:44:09Z DEBUG 6 2018-02-15T06:44:09Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:09Z DEBUG 8192 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:09Z DEBUG month 2018-02-15T06:44:09Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG passwordMaxAge: 2018-02-15T06:44:09Z DEBUG 8640000 2018-02-15T06:44:09Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:09Z DEBUG gidNumber 2018-02-15T06:44:09Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:09Z DEBUG day 2018-02-15T06:44:09Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:09Z DEBUG /tmp 2018-02-15T06:44:09Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:09Z DEBUG 600 2018-02-15T06:44:09Z DEBUG nsslapd-counters: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:09Z DEBUG month 2018-02-15T06:44:09Z DEBUG nsslapd-minssf: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:09Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:09Z DEBUG nsslapd-localuser: 2018-02-15T06:44:09Z DEBUG dirsrv 2018-02-15T06:44:09Z DEBUG nsslapd-security: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordChange: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:09Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:09Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:09Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:09Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:09Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:09Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:09Z DEBUG passwordMaxFailure: 2018-02-15T06:44:09Z DEBUG 3 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:09Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:09Z DEBUG 128 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:09Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:09Z DEBUG cn=Directory Manager 2018-02-15T06:44:09Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:09Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:09Z DEBUG 600 2018-02-15T06:44:09Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:09Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG passwordMustChange: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordExp: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:09Z DEBUG dirsrv-log 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:09Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG aci: 2018-02-15T06:44:09Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:09Z DEBUG cn=Directory Manager 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordMinLength: 2018-02-15T06:44:09Z DEBUG 8 2018-02-15T06:44:09Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:09Z DEBUG -10 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:09Z DEBUG week 2018-02-15T06:44:09Z DEBUG nsslapd-securePort: 2018-02-15T06:44:09Z DEBUG 636 2018-02-15T06:44:09Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG cn: 2018-02-15T06:44:09Z DEBUG config 2018-02-15T06:44:09Z DEBUG objectClass: 2018-02-15T06:44:09Z DEBUG top 2018-02-15T06:44:09Z DEBUG extensibleObject 2018-02-15T06:44:09Z DEBUG nsslapdConfig 2018-02-15T06:44:09Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:09Z DEBUG next 2018-02-15T06:44:09Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:09Z DEBUG -10 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:09Z DEBUG 5 2018-02-15T06:44:09Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:09Z DEBUG 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:09Z DEBUG 600 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:09Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG passwordGraceLimit: 2018-02-15T06:44:09Z DEBUG 0 2018-02-15T06:44:09Z DEBUG passwordWarning: 2018-02-15T06:44:09Z DEBUG 86400 2018-02-15T06:44:09Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:09Z DEBUG 600 2018-02-15T06:44:09Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:09Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:09Z DEBUG nsslapd-config: 2018-02-15T06:44:09Z DEBUG cn=config 2018-02-15T06:44:09Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:09Z DEBUG 100 2018-02-15T06:44:09Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:09Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:09Z DEBUG 256 2018-02-15T06:44:09Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:09Z DEBUG on 2018-02-15T06:44:09Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:09Z DEBUG 2097152 2018-02-15T06:44:09Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:09Z DEBUG month 2018-02-15T06:44:09Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:09Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:09Z DEBUG SSHA512 2018-02-15T06:44:09Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:09Z DEBUG 1 2018-02-15T06:44:09Z DEBUG passwordLockout: 2018-02-15T06:44:09Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:10Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-certdir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:10Z DEBUG 16 2018-02-15T06:44:10Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-localhost: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:10Z DEBUG passwordMin8bit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:10Z DEBUG warn 2018-02-15T06:44:10Z DEBUG passwordMinCategories: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG passwordMinLowers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordAdminDN: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinSpecials: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:10Z DEBUG none 2018-02-15T06:44:10Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG passwordUnlock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:10Z DEBUG dc=example,dc=com 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-localssf: 2018-02-15T06:44:10Z DEBUG 71 2018-02-15T06:44:10Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:10Z DEBUG 2000 2018-02-15T06:44:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-port: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:10Z DEBUG cn=schema 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG cn=monitor 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:10Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:10Z DEBUG 300000 2018-02-15T06:44:10Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-rundir: 2018-02-15T06:44:10Z DEBUG /var/run/dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:10Z DEBUG replication-only 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:10Z DEBUG 16384 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:10Z DEBUG 10000 2018-02-15T06:44:10Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinDigits: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG passwordStorageScheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG [(2, u'aci', [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)'])] 2018-02-15T06:44:10Z DEBUG Updated 1 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG retrieve certificate 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG retrieve certificate 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG request certificate 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG request certificate 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG request certificate different host 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG request certificate different host 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG certificate status 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG certificate status 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG revoke certificate 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG revoke certificate 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG certificate remove hold 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG certificate remove hold 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG request certificate ignore caacl 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG request certificate ignore caacl 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Request Certificate ignoring CA ACLs 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Request Certificate ignoring CA ACLs 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG info: 2018-02-15T06:44:10Z DEBUG IPA V2.0 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG domain 2018-02-15T06:44:10Z DEBUG pilotObject 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nisDomainObject 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG dc: 2018-02-15T06:44:10Z DEBUG pytest 2018-02-15T06:44:10Z DEBUG nisDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG add: '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG info: 2018-02-15T06:44:10Z DEBUG IPA V2.0 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG domain 2018-02-15T06:44:10Z DEBUG pilotObject 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nisDomainObject 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG dc: 2018-02-15T06:44:10Z DEBUG pytest 2018-02-15T06:44:10Z DEBUG nisDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=RBAC Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read roles, privileges, permissions and ACIs 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG RBAC Readers 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read roles, privileges, permissions and ACIs 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG RBAC Readers 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read password policies 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Password Policy Readers 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read password policies 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Password Policy Readers 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read global and per-user Kerberos ticket policy 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Kerberos Ticket Policy Readers 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read global and per-user Kerberos ticket policy 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Kerberos Ticket Policy Readers 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Automember Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read Automember definitions 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Automember Readers 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read Automember definitions 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Automember Readers 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read list of IPA masters 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA Masters Readers 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Read list of IPA masters 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA Masters Readers 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG masters 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' from aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=replica3.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:10Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG masters 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=PassSync Service,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG PassSync Service 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG PassSync Service 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG PassSync Service 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG PassSync Service 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Read PassSync Managers Configuration 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Read PassSync Managers Configuration 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-betype: 2018-02-15T06:44:10Z DEBUG ldbm database 2018-02-15T06:44:10Z DEBUG nsslapd-nagle: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:10Z DEBUG 64 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG passwordMinAlphas: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:10Z DEBUG allowed 2018-02-15T06:44:10Z DEBUG passwordMinUppers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin: 2018-02-15T06:44:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:10Z DEBUG 20971520 2018-02-15T06:44:10Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMinAge: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:10Z DEBUG 60 2018-02-15T06:44:10Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordInHistory: 2018-02-15T06:44:10Z DEBUG 6 2018-02-15T06:44:10Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG passwordMaxAge: 2018-02-15T06:44:10Z DEBUG 8640000 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG day 2018-02-15T06:44:10Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:10Z DEBUG /tmp 2018-02-15T06:44:10Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-counters: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-minssf: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:10Z DEBUG nsslapd-localuser: 2018-02-15T06:44:10Z DEBUG dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-security: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordChange: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:10Z DEBUG passwordMaxFailure: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:10Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:10Z DEBUG 128 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:10Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:10Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMustChange: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordExp: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:10Z DEBUG dirsrv-log 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinLength: 2018-02-15T06:44:10Z DEBUG 8 2018-02-15T06:44:10Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-securePort: 2018-02-15T06:44:10Z DEBUG 636 2018-02-15T06:44:10Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapdConfig 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:10Z DEBUG next 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordGraceLimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG passwordWarning: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-config: 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:10Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:10Z DEBUG 256 2018-02-15T06:44:10Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordLockout: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:10Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-certdir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:10Z DEBUG 16 2018-02-15T06:44:10Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-localhost: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:10Z DEBUG passwordMin8bit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:10Z DEBUG warn 2018-02-15T06:44:10Z DEBUG passwordMinCategories: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG passwordMinLowers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordAdminDN: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinSpecials: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:10Z DEBUG none 2018-02-15T06:44:10Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG passwordUnlock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:10Z DEBUG dc=example,dc=com 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-localssf: 2018-02-15T06:44:10Z DEBUG 71 2018-02-15T06:44:10Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:10Z DEBUG 2000 2018-02-15T06:44:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-port: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:10Z DEBUG cn=schema 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG cn=monitor 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:10Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:10Z DEBUG 300000 2018-02-15T06:44:10Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-rundir: 2018-02-15T06:44:10Z DEBUG /var/run/dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:10Z DEBUG replication-only 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:10Z DEBUG 16384 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:10Z DEBUG 10000 2018-02-15T06:44:10Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinDigits: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG passwordStorageScheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-betype: 2018-02-15T06:44:10Z DEBUG ldbm database 2018-02-15T06:44:10Z DEBUG nsslapd-nagle: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:10Z DEBUG 64 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG passwordMinAlphas: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:10Z DEBUG allowed 2018-02-15T06:44:10Z DEBUG passwordMinUppers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin: 2018-02-15T06:44:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:10Z DEBUG 20971520 2018-02-15T06:44:10Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMinAge: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:10Z DEBUG 60 2018-02-15T06:44:10Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordInHistory: 2018-02-15T06:44:10Z DEBUG 6 2018-02-15T06:44:10Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG passwordMaxAge: 2018-02-15T06:44:10Z DEBUG 8640000 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG day 2018-02-15T06:44:10Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:10Z DEBUG /tmp 2018-02-15T06:44:10Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-counters: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-minssf: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:10Z DEBUG nsslapd-localuser: 2018-02-15T06:44:10Z DEBUG dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-security: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordChange: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:10Z DEBUG passwordMaxFailure: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:10Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:10Z DEBUG 128 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:10Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:10Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMustChange: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordExp: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:10Z DEBUG dirsrv-log 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinLength: 2018-02-15T06:44:10Z DEBUG 8 2018-02-15T06:44:10Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-securePort: 2018-02-15T06:44:10Z DEBUG 636 2018-02-15T06:44:10Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapdConfig 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:10Z DEBUG next 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordGraceLimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG passwordWarning: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-config: 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:10Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:10Z DEBUG 256 2018-02-15T06:44:10Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordLockout: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:10Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-certdir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:10Z DEBUG 16 2018-02-15T06:44:10Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-localhost: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:10Z DEBUG passwordMin8bit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:10Z DEBUG warn 2018-02-15T06:44:10Z DEBUG passwordMinCategories: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG passwordMinLowers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordAdminDN: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinSpecials: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:10Z DEBUG none 2018-02-15T06:44:10Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG passwordUnlock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:10Z DEBUG dc=example,dc=com 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-localssf: 2018-02-15T06:44:10Z DEBUG 71 2018-02-15T06:44:10Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:10Z DEBUG 2000 2018-02-15T06:44:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-port: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:10Z DEBUG cn=schema 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG cn=monitor 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:10Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:10Z DEBUG 300000 2018-02-15T06:44:10Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-rundir: 2018-02-15T06:44:10Z DEBUG /var/run/dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:10Z DEBUG replication-only 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:10Z DEBUG 16384 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:10Z DEBUG 10000 2018-02-15T06:44:10Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinDigits: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG passwordStorageScheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG [(0, u'aci', [u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'])] 2018-02-15T06:44:10Z DEBUG Updated 1 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Modify PassSync Managers Configuration 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Modify PassSync Managers Configuration 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-betype: 2018-02-15T06:44:10Z DEBUG ldbm database 2018-02-15T06:44:10Z DEBUG nsslapd-nagle: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:10Z DEBUG 64 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG passwordMinAlphas: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:10Z DEBUG allowed 2018-02-15T06:44:10Z DEBUG passwordMinUppers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin: 2018-02-15T06:44:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:10Z DEBUG 20971520 2018-02-15T06:44:10Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMinAge: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:10Z DEBUG 60 2018-02-15T06:44:10Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordInHistory: 2018-02-15T06:44:10Z DEBUG 6 2018-02-15T06:44:10Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG passwordMaxAge: 2018-02-15T06:44:10Z DEBUG 8640000 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG day 2018-02-15T06:44:10Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:10Z DEBUG /tmp 2018-02-15T06:44:10Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-counters: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-minssf: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:10Z DEBUG nsslapd-localuser: 2018-02-15T06:44:10Z DEBUG dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-security: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordChange: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:10Z DEBUG passwordMaxFailure: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:10Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:10Z DEBUG 128 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:10Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:10Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMustChange: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordExp: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:10Z DEBUG dirsrv-log 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinLength: 2018-02-15T06:44:10Z DEBUG 8 2018-02-15T06:44:10Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-securePort: 2018-02-15T06:44:10Z DEBUG 636 2018-02-15T06:44:10Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapdConfig 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:10Z DEBUG next 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordGraceLimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG passwordWarning: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-config: 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:10Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:10Z DEBUG 256 2018-02-15T06:44:10Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordLockout: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:10Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-certdir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:10Z DEBUG 16 2018-02-15T06:44:10Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-localhost: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:10Z DEBUG passwordMin8bit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:10Z DEBUG warn 2018-02-15T06:44:10Z DEBUG passwordMinCategories: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG passwordMinLowers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordAdminDN: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinSpecials: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:10Z DEBUG none 2018-02-15T06:44:10Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG passwordUnlock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:10Z DEBUG dc=example,dc=com 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-localssf: 2018-02-15T06:44:10Z DEBUG 71 2018-02-15T06:44:10Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:10Z DEBUG 2000 2018-02-15T06:44:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-port: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:10Z DEBUG cn=schema 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG cn=monitor 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:10Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:10Z DEBUG 300000 2018-02-15T06:44:10Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-rundir: 2018-02-15T06:44:10Z DEBUG /var/run/dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:10Z DEBUG replication-only 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:10Z DEBUG 16384 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:10Z DEBUG 10000 2018-02-15T06:44:10Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinDigits: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG passwordStorageScheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG add: '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-betype: 2018-02-15T06:44:10Z DEBUG ldbm database 2018-02-15T06:44:10Z DEBUG nsslapd-nagle: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:10Z DEBUG 64 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG passwordMinAlphas: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:10Z DEBUG allowed 2018-02-15T06:44:10Z DEBUG passwordMinUppers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin: 2018-02-15T06:44:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:10Z DEBUG 20971520 2018-02-15T06:44:10Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMinAge: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:10Z DEBUG 60 2018-02-15T06:44:10Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordInHistory: 2018-02-15T06:44:10Z DEBUG 6 2018-02-15T06:44:10Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG passwordMaxAge: 2018-02-15T06:44:10Z DEBUG 8640000 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG day 2018-02-15T06:44:10Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:10Z DEBUG /tmp 2018-02-15T06:44:10Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-counters: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-minssf: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:10Z DEBUG nsslapd-localuser: 2018-02-15T06:44:10Z DEBUG dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-security: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordChange: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:10Z DEBUG passwordMaxFailure: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:10Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:10Z DEBUG 128 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:10Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:10Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMustChange: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordExp: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:10Z DEBUG dirsrv-log 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinLength: 2018-02-15T06:44:10Z DEBUG 8 2018-02-15T06:44:10Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-securePort: 2018-02-15T06:44:10Z DEBUG 636 2018-02-15T06:44:10Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapdConfig 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:10Z DEBUG next 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordGraceLimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG passwordWarning: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-config: 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:10Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:10Z DEBUG 256 2018-02-15T06:44:10Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordLockout: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:10Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-certdir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:10Z DEBUG 16 2018-02-15T06:44:10Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-localhost: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:10Z DEBUG passwordMin8bit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:10Z DEBUG warn 2018-02-15T06:44:10Z DEBUG passwordMinCategories: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG passwordMinLowers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordAdminDN: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinSpecials: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:10Z DEBUG none 2018-02-15T06:44:10Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG passwordUnlock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:10Z DEBUG dc=example,dc=com 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-localssf: 2018-02-15T06:44:10Z DEBUG 71 2018-02-15T06:44:10Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:10Z DEBUG 2000 2018-02-15T06:44:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-port: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:10Z DEBUG cn=schema 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG cn=monitor 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:10Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:10Z DEBUG 300000 2018-02-15T06:44:10Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-rundir: 2018-02-15T06:44:10Z DEBUG /var/run/dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:10Z DEBUG replication-only 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:10Z DEBUG 16384 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:10Z DEBUG 10000 2018-02-15T06:44:10Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinDigits: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG passwordStorageScheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG [(0, u'aci', [u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'])] 2018-02-15T06:44:10Z DEBUG Updated 1 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Read LDBM Database Configuration 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Read LDBM Database Configuration 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-betype: 2018-02-15T06:44:10Z DEBUG ldbm database 2018-02-15T06:44:10Z DEBUG nsslapd-nagle: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:10Z DEBUG 64 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG passwordMinAlphas: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:10Z DEBUG allowed 2018-02-15T06:44:10Z DEBUG passwordMinUppers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin: 2018-02-15T06:44:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:10Z DEBUG 20971520 2018-02-15T06:44:10Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMinAge: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:10Z DEBUG 60 2018-02-15T06:44:10Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordInHistory: 2018-02-15T06:44:10Z DEBUG 6 2018-02-15T06:44:10Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG passwordMaxAge: 2018-02-15T06:44:10Z DEBUG 8640000 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG day 2018-02-15T06:44:10Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:10Z DEBUG /tmp 2018-02-15T06:44:10Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-counters: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-minssf: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:10Z DEBUG nsslapd-localuser: 2018-02-15T06:44:10Z DEBUG dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-security: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordChange: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:10Z DEBUG passwordMaxFailure: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:10Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:10Z DEBUG 128 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:10Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:10Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMustChange: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordExp: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:10Z DEBUG dirsrv-log 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinLength: 2018-02-15T06:44:10Z DEBUG 8 2018-02-15T06:44:10Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-securePort: 2018-02-15T06:44:10Z DEBUG 636 2018-02-15T06:44:10Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapdConfig 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:10Z DEBUG next 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordGraceLimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG passwordWarning: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-config: 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:10Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:10Z DEBUG 256 2018-02-15T06:44:10Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordLockout: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:10Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-certdir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:10Z DEBUG 16 2018-02-15T06:44:10Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-localhost: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:10Z DEBUG passwordMin8bit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:10Z DEBUG warn 2018-02-15T06:44:10Z DEBUG passwordMinCategories: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG passwordMinLowers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordAdminDN: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinSpecials: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:10Z DEBUG none 2018-02-15T06:44:10Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG passwordUnlock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:10Z DEBUG dc=example,dc=com 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-localssf: 2018-02-15T06:44:10Z DEBUG 71 2018-02-15T06:44:10Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:10Z DEBUG 2000 2018-02-15T06:44:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-port: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:10Z DEBUG cn=schema 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG cn=monitor 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:10Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:10Z DEBUG 300000 2018-02-15T06:44:10Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-rundir: 2018-02-15T06:44:10Z DEBUG /var/run/dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:10Z DEBUG replication-only 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:10Z DEBUG 16384 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:10Z DEBUG 10000 2018-02-15T06:44:10Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinDigits: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG passwordStorageScheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-betype: 2018-02-15T06:44:10Z DEBUG ldbm database 2018-02-15T06:44:10Z DEBUG nsslapd-nagle: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:10Z DEBUG 64 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG passwordMinAlphas: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:10Z DEBUG allowed 2018-02-15T06:44:10Z DEBUG passwordMinUppers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin: 2018-02-15T06:44:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:10Z DEBUG 20971520 2018-02-15T06:44:10Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMinAge: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:10Z DEBUG 60 2018-02-15T06:44:10Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordInHistory: 2018-02-15T06:44:10Z DEBUG 6 2018-02-15T06:44:10Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG passwordMaxAge: 2018-02-15T06:44:10Z DEBUG 8640000 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG day 2018-02-15T06:44:10Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:10Z DEBUG /tmp 2018-02-15T06:44:10Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-counters: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-minssf: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:10Z DEBUG nsslapd-localuser: 2018-02-15T06:44:10Z DEBUG dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-security: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordChange: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:10Z DEBUG passwordMaxFailure: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:10Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:10Z DEBUG 128 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:10Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:10Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMustChange: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordExp: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:10Z DEBUG dirsrv-log 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinLength: 2018-02-15T06:44:10Z DEBUG 8 2018-02-15T06:44:10Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-securePort: 2018-02-15T06:44:10Z DEBUG 636 2018-02-15T06:44:10Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapdConfig 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:10Z DEBUG next 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordGraceLimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG passwordWarning: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-config: 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:10Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:10Z DEBUG 256 2018-02-15T06:44:10Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordLockout: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:10Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-certdir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:10Z DEBUG 16 2018-02-15T06:44:10Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-localhost: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:10Z DEBUG passwordMin8bit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:10Z DEBUG warn 2018-02-15T06:44:10Z DEBUG passwordMinCategories: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG passwordMinLowers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordAdminDN: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinSpecials: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:10Z DEBUG none 2018-02-15T06:44:10Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG passwordUnlock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:10Z DEBUG dc=example,dc=com 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-localssf: 2018-02-15T06:44:10Z DEBUG 71 2018-02-15T06:44:10Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:10Z DEBUG 2000 2018-02-15T06:44:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-port: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:10Z DEBUG cn=schema 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG cn=monitor 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:10Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:10Z DEBUG 300000 2018-02-15T06:44:10Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-rundir: 2018-02-15T06:44:10Z DEBUG /var/run/dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:10Z DEBUG replication-only 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:10Z DEBUG 16384 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:10Z DEBUG 10000 2018-02-15T06:44:10Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinDigits: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG passwordStorageScheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG [(0, u'aci', [u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'])] 2018-02-15T06:44:10Z DEBUG Updated 1 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Add Configuration Sub-Entries 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Add Configuration Sub-Entries 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-betype: 2018-02-15T06:44:10Z DEBUG ldbm database 2018-02-15T06:44:10Z DEBUG nsslapd-nagle: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:10Z DEBUG 64 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG passwordMinAlphas: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:10Z DEBUG allowed 2018-02-15T06:44:10Z DEBUG passwordMinUppers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin: 2018-02-15T06:44:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:10Z DEBUG 20971520 2018-02-15T06:44:10Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMinAge: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:10Z DEBUG 60 2018-02-15T06:44:10Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordInHistory: 2018-02-15T06:44:10Z DEBUG 6 2018-02-15T06:44:10Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG passwordMaxAge: 2018-02-15T06:44:10Z DEBUG 8640000 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG day 2018-02-15T06:44:10Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:10Z DEBUG /tmp 2018-02-15T06:44:10Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-counters: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-minssf: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:10Z DEBUG nsslapd-localuser: 2018-02-15T06:44:10Z DEBUG dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-security: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordChange: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:10Z DEBUG passwordMaxFailure: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:10Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:10Z DEBUG 128 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:10Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:10Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMustChange: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordExp: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:10Z DEBUG dirsrv-log 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinLength: 2018-02-15T06:44:10Z DEBUG 8 2018-02-15T06:44:10Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-securePort: 2018-02-15T06:44:10Z DEBUG 636 2018-02-15T06:44:10Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapdConfig 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:10Z DEBUG next 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordGraceLimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG passwordWarning: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-config: 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:10Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:10Z DEBUG 256 2018-02-15T06:44:10Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordLockout: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:10Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-certdir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:10Z DEBUG 16 2018-02-15T06:44:10Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-localhost: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:10Z DEBUG passwordMin8bit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:10Z DEBUG warn 2018-02-15T06:44:10Z DEBUG passwordMinCategories: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG passwordMinLowers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordAdminDN: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinSpecials: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:10Z DEBUG none 2018-02-15T06:44:10Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG passwordUnlock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:10Z DEBUG dc=example,dc=com 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-localssf: 2018-02-15T06:44:10Z DEBUG 71 2018-02-15T06:44:10Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:10Z DEBUG 2000 2018-02-15T06:44:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-port: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:10Z DEBUG cn=schema 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG cn=monitor 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:10Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:10Z DEBUG 300000 2018-02-15T06:44:10Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-rundir: 2018-02-15T06:44:10Z DEBUG /var/run/dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:10Z DEBUG replication-only 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:10Z DEBUG 16384 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:10Z DEBUG 10000 2018-02-15T06:44:10Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinDigits: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG passwordStorageScheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG add: '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-betype: 2018-02-15T06:44:10Z DEBUG ldbm database 2018-02-15T06:44:10Z DEBUG nsslapd-nagle: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-global: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-referralmode: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-reservedescriptors: 2018-02-15T06:44:10Z DEBUG 64 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG passwordMinAlphas: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-enquote-sup-oc: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxcheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-unhashed-pw-switch: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordLegacyPolicy: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logbuffering: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-SSLclientAuth: 2018-02-15T06:44:10Z DEBUG allowed 2018-02-15T06:44:10Z DEBUG passwordMinUppers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin: 2018-02-15T06:44:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-threshold: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-dn-validate-strict: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-max-size: 2018-02-15T06:44:10Z DEBUG 20971520 2018-02-15T06:44:10Z DEBUG nsslapd-timelimit: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordIsGlobalPolicy: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-moddn-aci: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinTokenLength: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mxfast: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMinAge: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2018-02-15T06:44:10Z DEBUG 60 2018-02-15T06:44:10Z DEBUG nsslapd-maxdescriptors: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-allow-hashed-passwords: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordInHistory: 2018-02-15T06:44:10Z DEBUG 6 2018-02-15T06:44:10Z DEBUG nsslapd-ssl-check-hostname: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-conntablesize: 2018-02-15T06:44:10Z DEBUG 8192 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-saslpath: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG passwordMaxAge: 2018-02-15T06:44:10Z DEBUG 8640000 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiautobind: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-extract-pemfiles: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxthreadsperconn: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapigidnumbertype: 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-connection-buffer: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG day 2018-02-15T06:44:10Z DEBUG nsslapd-dynamic-plugins: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-csnlogging: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-tmpdir: 2018-02-15T06:44:10Z DEBUG /tmp 2018-02-15T06:44:10Z DEBUG passwordResetFailureCount: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-counters: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-svrtab: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-minssf: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-schemadir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST/schema 2018-02-15T06:44:10Z DEBUG nsslapd-localuser: 2018-02-15T06:44:10Z DEBUG dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-security: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordChange: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-requiresrestart: 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-port 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-secureport 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapifilepath 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-ldapilisten 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-workingdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-sslclientauth 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogdir 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogsuffix 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-changelogmaxage 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-db-locks 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-maxdescriptors 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-return-exact-case 2018-02-15T06:44:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2018-02-15T06:44:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl2 2018-02-15T06:44:10Z DEBUG cn=encryption,cn=config:nsssl3 2018-02-15T06:44:10Z DEBUG passwordMaxFailure: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ldapifilepath: 2018-02-15T06:44:10Z DEBUG /var/run/slapd-PYTEST-TEST.socket 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-pagedsizelimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-global-backend-lock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listen-backlog-size: 2018-02-15T06:44:10Z DEBUG 128 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/access 2018-02-15T06:44:10Z DEBUG nsslapd-certmap-basedn: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-logging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesscontrol: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-rootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-ldifdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/ldif 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-anonlimitsdn: 2018-02-15T06:44:10Z DEBUG cn=anonymous-limits,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logging-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordMustChange: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordExp: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-logging-backend: 2018-02-15T06:44:10Z DEBUG dirsrv-log 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaprootdn: 2018-02-15T06:44:10Z DEBUG cn=Directory Manager 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ds4-compatible-schema: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-nunc-stans: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinLength: 2018-02-15T06:44:10Z DEBUG 8 2018-02-15T06:44:10Z DEBUG nsslapd-require-secure-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-groupevalnestlevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-idletimeout: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-mmap-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2018-02-15T06:44:10Z DEBUG week 2018-02-15T06:44:10Z DEBUG nsslapd-securePort: 2018-02-15T06:44:10Z DEBUG 636 2018-02-15T06:44:10Z DEBUG nsslapd-snmp-index: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapdConfig 2018-02-15T06:44:10Z DEBUG nsslapd-ldapimaptoentries: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordSendExpiringTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-hash-filters: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-entryusn-import-initval: 2018-02-15T06:44:10Z DEBUG next 2018-02-15T06:44:10Z DEBUG nsslapd-malloc-trim-threshold: 2018-02-15T06:44:10Z DEBUG -10 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-time-skew: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-listenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/errors 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-mapping-fallback: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-force-sasl-external: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-enable-turbo-mode: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordCheckSyntax: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordGraceLimit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG passwordWarning: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-instancedir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/scripts-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-config: 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-versionstring: 2018-02-15T06:44:10Z DEBUG 389-Directory/1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-level: 2018-02-15T06:44:10Z DEBUG 256 2018-02-15T06:44:10Z DEBUG nsslapd-return-exact-case: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-maxsasliosize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG nsslapd-rewrite-rfc1274: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-rootpwstoragescheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG passwordLockout: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-lockdir: 2018-02-15T06:44:10Z DEBUG /var/lock/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-certdir: 2018-02-15T06:44:10Z DEBUG /etc/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-allow-anonymous-access: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG nsslapd-backendconfig: 2018-02-15T06:44:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-threadnumber: 2018-02-15T06:44:10Z DEBUG 16 2018-02-15T06:44:10Z DEBUG nsslapd-schemamod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-search-return-original-type-switch: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-localhost: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG nsslapd-bakdir: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/bak 2018-02-15T06:44:10Z DEBUG passwordMin8bit: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ldapiuidnumbertype: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG nsslapd-validate-cert: 2018-02-15T06:44:10Z DEBUG warn 2018-02-15T06:44:10Z DEBUG passwordMinCategories: 2018-02-15T06:44:10Z DEBUG 3 2018-02-15T06:44:10Z DEBUG passwordMinLowers: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordAdminDN: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-ldapilisten: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordMinSpecials: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-lastmod: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-max-filter-nest-level: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG passwordMaxRepeats: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-securelistenhost: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-tls-check-crl: 2018-02-15T06:44:10Z DEBUG none 2018-02-15T06:44:10Z DEBUG nsslapd-result-tweak: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2018-02-15T06:44:10Z DEBUG month 2018-02-15T06:44:10Z DEBUG passwordUnlock: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-schemacheck: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG passwordTrackUpdateTime: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-maxbersize: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-ldapientrysearchbase: 2018-02-15T06:44:10Z DEBUG dc=example,dc=com 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-localssf: 2018-02-15T06:44:10Z DEBUG 71 2018-02-15T06:44:10Z DEBUG nsslapd-sizelimit: 2018-02-15T06:44:10Z DEBUG 2000 2018-02-15T06:44:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-ignore-virtual-attrs: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ndn-cache-enabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-defaultnamingcontext: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-pwpolicy-local: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-sasl-max-buffer-size: 2018-02-15T06:44:10Z DEBUG 2097152 2018-02-15T06:44:10Z DEBUG passwordLockoutDuration: 2018-02-15T06:44:10Z DEBUG 3600 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-port: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-maxlogsize: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG nsslapd-privatenamespaces: 2018-02-15T06:44:10Z DEBUG cn=schema 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG cn=monitor 2018-02-15T06:44:10Z DEBUG cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG nsslapd-auditlog: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST/audit 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-mode: 2018-02-15T06:44:10Z DEBUG 600 2018-02-15T06:44:10Z DEBUG nsslapd-rootpw: 2018-02-15T06:44:10Z DEBUG {SSHA512}pimJx6V43cS2HRVgbL4iZLL71Iyam6+DUizrNldTKBROJ/2Z8oFYoHYVkFSKMdL2SAa1KUdjphmGvIEi6bFuN5Kpt4VQQlf8 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2018-02-15T06:44:10Z DEBUG 300000 2018-02-15T06:44:10Z DEBUG nsslapd-workingdir: 2018-02-15T06:44:10Z DEBUG /var/log/dirsrv/slapd-PYTEST-TEST 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-list: 2018-02-15T06:44:10Z DEBUG 2018-02-15T06:44:10Z DEBUG nsslapd-rundir: 2018-02-15T06:44:10Z DEBUG /var/run/dirsrv 2018-02-15T06:44:10Z DEBUG nsslapd-schemareplace: 2018-02-15T06:44:10Z DEBUG replication-only 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-binddn-tracking: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-errorlog-level: 2018-02-15T06:44:10Z DEBUG 16384 2018-02-15T06:44:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-syntaxlogging: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-ioblocktimeout: 2018-02-15T06:44:10Z DEBUG 10000 2018-02-15T06:44:10Z DEBUG nsslapd-attribute-name-exceptions: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG passwordMinDigits: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2018-02-15T06:44:10Z DEBUG 5 2018-02-15T06:44:10Z DEBUG passwordStorageScheme: 2018-02-15T06:44:10Z DEBUG SSHA512 2018-02-15T06:44:10Z DEBUG nsslapd-connection-nocanon: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG [(0, u'aci', [u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)'])] 2018-02-15T06:44:10Z DEBUG Updated 1 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=CA Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG CA Administrator 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG CA Administrator 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG CA Administrator 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG CA Administrator 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Vault Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Vault Administrators 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Vault Administrators 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Vault Administrators 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Vault Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=DNS Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG DNS Administrators 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG DNS Administrators 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG DNS Administrators 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG DNS Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=DNS Servers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG krbprincipalname=DNS/master.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbprincipalname=ipa-dnskeysyncd/master.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbprincipalname=DNS/replica.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbprincipalname=ipa-dnskeysyncd/replica.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG DNS Servers 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG DNS Servers 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG krbprincipalname=DNS/master.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbprincipalname=ipa-dnskeysyncd/master.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbprincipalname=DNS/replica.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbprincipalname=ipa-dnskeysyncd/replica.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG DNS Servers 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG DNS Servers 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/40-dns.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=dns,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=dns,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG idnsConfigObject 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaDNSContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG DNSVersion 1 2018-02-15T06:44:10Z DEBUG ipaDNSVersion: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG dns 2018-02-15T06:44:10Z DEBUG addifexist: 'idnsConfigObject' to objectClass, current value [u'idnsConfigObject', u'nsContainer', u'ipaConfigObject', u'ipaDNSContainer', u'top'] 2018-02-15T06:44:10Z DEBUG addifexist: set objectClass to [u'idnsConfigObject', u'nsContainer', u'ipaConfigObject', u'ipaDNSContainer', u'top', u'idnsConfigObject'] 2018-02-15T06:44:10Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG addifexist: set aci to [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG addifexist: set aci to [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' to aci, current value [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG addifexist: set aci to [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=dns,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG idnsConfigObject 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaDNSContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG DNSVersion 1 2018-02-15T06:44:10Z DEBUG ipaDNSVersion: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG dns 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=dns,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=dns,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG idnsConfigObject 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaDNSContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG DNSVersion 1 2018-02-15T06:44:10Z DEBUG ipaDNSVersion: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG dns 2018-02-15T06:44:10Z DEBUG replace: (targetattr = "*")(version 3.0; acl "No access to DNS tree without a permission"; deny (read,search,compare) (groupdn != "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test") and (groupdn != "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test");) not found, skipping 2018-02-15T06:44:10Z DEBUG replace: (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";) not found, skipping 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=dns,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG idnsConfigObject 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaDNSContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG DNSVersion 1 2018-02-15T06:44:10Z DEBUG ipaDNSVersion: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG dns 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=dns,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=dns,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG idnsConfigObject 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaDNSContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG DNSVersion 1 2018-02-15T06:44:10Z DEBUG ipaDNSVersion: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG dns 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', u'(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=dns,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG idnsConfigObject 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaDNSContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG DNSVersion 1 2018-02-15T06:44:10Z DEBUG ipaDNSVersion: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG dns 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=IPA DNS,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:10Z DEBUG ipa_dns 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA DNS 2018-02-15T06:44:10Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:10Z DEBUG 1.0 2018-02-15T06:44:10Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:10Z DEBUG IPA DNS support plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:10Z DEBUG libipa_dns.so 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsslapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:10Z DEBUG Red Hat, Inc. 2018-02-15T06:44:10Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:10Z DEBUG preoperation 2018-02-15T06:44:10Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:10Z DEBUG ipadns_init 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:10Z DEBUG ipa_dns 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA DNS 2018-02-15T06:44:10Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:10Z DEBUG 1.0 2018-02-15T06:44:10Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:10Z DEBUG IPA DNS support plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:10Z DEBUG libipa_dns.so 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsslapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:10Z DEBUG Red Hat, Inc. 2018-02-15T06:44:10Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:10Z DEBUG preoperation 2018-02-15T06:44:10Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:10Z DEBUG ipadns_init 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/40-otp.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=otp,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=otp,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG otp 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=otp,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG otp 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=otp,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=otp,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipatokenHOTPsyncWindow: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG ipatokenHOTPauthWindow: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG otp 2018-02-15T06:44:10Z DEBUG ipatokenTOTPsyncWindow: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipatokenOTPConfig 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || ipatokenhotpauthwindow || ipatokenhotpsyncwindow || ipatokentotpauthwindow || ipatokentotpsyncwindow")(targetfilter = "(objectclass=ipatokenotpconfig)")(version 3.0;acl "permission:System: Read OTP Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG ipatokenTOTPauthWindow: 2018-02-15T06:44:10Z DEBUG 300 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=otp,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipatokenHOTPsyncWindow: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG ipatokenHOTPauthWindow: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG otp 2018-02-15T06:44:10Z DEBUG ipatokenTOTPsyncWindow: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipatokenOTPConfig 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || ipatokenhotpauthwindow || ipatokenhotpsyncwindow || ipatokentotpauthwindow || ipatokentotpsyncwindow")(targetfilter = "(objectclass=ipatokenotpconfig)")(version 3.0;acl "permission:System: Read OTP Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG ipatokenTOTPauthWindow: 2018-02-15T06:44:10Z DEBUG 300 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG info: 2018-02-15T06:44:10Z DEBUG IPA V2.0 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG domain 2018-02-15T06:44:10Z DEBUG pilotObject 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nisDomainObject 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG dc: 2018-02-15T06:44:10Z DEBUG pytest 2018-02-15T06:44:10Z DEBUG nisDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:10Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2018-02-15T06:44:10Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG info: 2018-02-15T06:44:10Z DEBUG IPA V2.0 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG domain 2018-02-15T06:44:10Z DEBUG pilotObject 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nisDomainObject 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG dc: 2018-02-15T06:44:10Z DEBUG pytest 2018-02-15T06:44:10Z DEBUG nisDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=radiusproxy,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=radiusproxy,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG radiusproxy 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=radiusproxy,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG radiusproxy 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG New entry: cn=IPA OTP Last Token,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginid: 2018-02-15T06:44:10Z DEBUG ipa-otp-lasttoken 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA OTP Last Token 2018-02-15T06:44:10Z DEBUG objectclass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugindescription: 2018-02-15T06:44:10Z DEBUG IPA OTP Last Token plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginenabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginpath: 2018-02-15T06:44:10Z DEBUG libipa_otp_lasttoken 2018-02-15T06:44:10Z DEBUG nsslapd-pluginversion: 2018-02-15T06:44:10Z DEBUG 1.0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginvendor: 2018-02-15T06:44:10Z DEBUG Red Hat, Inc. 2018-02-15T06:44:10Z DEBUG nsslapd-plugintype: 2018-02-15T06:44:10Z DEBUG preoperation 2018-02-15T06:44:10Z DEBUG nsslapd-plugininitfunc: 2018-02-15T06:44:10Z DEBUG ipa_otp_lasttoken_init 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginid: 2018-02-15T06:44:10Z DEBUG ipa-otp-lasttoken 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA OTP Last Token 2018-02-15T06:44:10Z DEBUG objectclass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugindescription: 2018-02-15T06:44:10Z DEBUG IPA OTP Last Token plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginenabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginpath: 2018-02-15T06:44:10Z DEBUG libipa_otp_lasttoken 2018-02-15T06:44:10Z DEBUG nsslapd-pluginversion: 2018-02-15T06:44:10Z DEBUG 1.0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginvendor: 2018-02-15T06:44:10Z DEBUG Red Hat, Inc. 2018-02-15T06:44:10Z DEBUG nsslapd-plugintype: 2018-02-15T06:44:10Z DEBUG preoperation 2018-02-15T06:44:10Z DEBUG nsslapd-plugininitfunc: 2018-02-15T06:44:10Z DEBUG ipa_otp_lasttoken_init 2018-02-15T06:44:10Z DEBUG New entry: cn=IPA OTP Counter,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginid: 2018-02-15T06:44:10Z DEBUG ipa-otp-counter 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA OTP Counter 2018-02-15T06:44:10Z DEBUG objectclass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugindescription: 2018-02-15T06:44:10Z DEBUG IPA OTP Counter plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginenabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginpath: 2018-02-15T06:44:10Z DEBUG libipa_otp_counter 2018-02-15T06:44:10Z DEBUG nsslapd-pluginversion: 2018-02-15T06:44:10Z DEBUG 1.0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginvendor: 2018-02-15T06:44:10Z DEBUG Red Hat, Inc. 2018-02-15T06:44:10Z DEBUG nsslapd-plugintype: 2018-02-15T06:44:10Z DEBUG preoperation 2018-02-15T06:44:10Z DEBUG nsslapd-plugininitfunc: 2018-02-15T06:44:10Z DEBUG ipa_otp_counter_init 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginid: 2018-02-15T06:44:10Z DEBUG ipa-otp-counter 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA OTP Counter 2018-02-15T06:44:10Z DEBUG objectclass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugindescription: 2018-02-15T06:44:10Z DEBUG IPA OTP Counter plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginenabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginpath: 2018-02-15T06:44:10Z DEBUG libipa_otp_counter 2018-02-15T06:44:10Z DEBUG nsslapd-pluginversion: 2018-02-15T06:44:10Z DEBUG 1.0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginvendor: 2018-02-15T06:44:10Z DEBUG Red Hat, Inc. 2018-02-15T06:44:10Z DEBUG nsslapd-plugintype: 2018-02-15T06:44:10Z DEBUG preoperation 2018-02-15T06:44:10Z DEBUG nsslapd-plugininitfunc: 2018-02-15T06:44:10Z DEBUG ipa_otp_counter_init 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/40-realm_domains.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Realm Domains,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "associateddomain")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Modify Realm Domains";allow (write) groupdn = "ldap:///cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "associateddomain || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Read Realm Domains";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Realm Domains 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "associateddomain")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Modify Realm Domains";allow (write) groupdn = "ldap:///cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "associateddomain || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Read Realm Domains";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Realm Domains 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/40-replication.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-directory: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/db/userRoot 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG userRoot 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsBackendInstance 2018-02-15T06:44:10Z DEBUG nsslapd-require-index: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-suffix: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-dncachememsize: 2018-02-15T06:44:10Z DEBUG 67108864 2018-02-15T06:44:10Z DEBUG nsslapd-cachesize: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-cachememsize: 2018-02-15T06:44:10Z DEBUG 603979776 2018-02-15T06:44:10Z DEBUG add: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-directory: 2018-02-15T06:44:10Z DEBUG /var/lib/dirsrv/slapd-PYTEST-TEST/db/userRoot 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG userRoot 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsBackendInstance 2018-02-15T06:44:10Z DEBUG nsslapd-require-index: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG nsslapd-suffix: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-readonly: 2018-02-15T06:44:10Z DEBUG off 2018-02-15T06:44:10Z DEBUG nsslapd-dncachememsize: 2018-02-15T06:44:10Z DEBUG 67108864 2018-02-15T06:44:10Z DEBUG nsslapd-cachesize: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG nsslapd-cachememsize: 2018-02-15T06:44:10Z DEBUG 603979776 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Modify DNA Range 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Modify DNA Range 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG dnaScope: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaThreshold: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Posix IDs 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG dnaMagicRegen: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG dnaNextValue: 2018-02-15T06:44:10Z DEBUG 1101 2018-02-15T06:44:10Z DEBUG dnaExcludeScope: 2018-02-15T06:44:10Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaFilter: 2018-02-15T06:44:10Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2018-02-15T06:44:10Z DEBUG dnaType: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG dnaMaxValue: 2018-02-15T06:44:10Z DEBUG 1100 2018-02-15T06:44:10Z DEBUG dnaSharedCfgDN: 2018-02-15T06:44:10Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG add: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG dnaScope: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaThreshold: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Posix IDs 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG dnaMagicRegen: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG dnaNextValue: 2018-02-15T06:44:10Z DEBUG 1101 2018-02-15T06:44:10Z DEBUG dnaExcludeScope: 2018-02-15T06:44:10Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaFilter: 2018-02-15T06:44:10Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2018-02-15T06:44:10Z DEBUG dnaType: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG dnaMaxValue: 2018-02-15T06:44:10Z DEBUG 1100 2018-02-15T06:44:10Z DEBUG dnaSharedCfgDN: 2018-02-15T06:44:10Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Read DNA Range 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipapermission 2018-02-15T06:44:10Z DEBUG ipaPermissionType: 2018-02-15T06:44:10Z DEBUG SYSTEM 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Read DNA Range 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG dnaScope: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaThreshold: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Posix IDs 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG dnaMagicRegen: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG dnaNextValue: 2018-02-15T06:44:10Z DEBUG 1101 2018-02-15T06:44:10Z DEBUG dnaExcludeScope: 2018-02-15T06:44:10Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaFilter: 2018-02-15T06:44:10Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2018-02-15T06:44:10Z DEBUG dnaType: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG dnaMaxValue: 2018-02-15T06:44:10Z DEBUG 1100 2018-02-15T06:44:10Z DEBUG dnaSharedCfgDN: 2018-02-15T06:44:10Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG add: '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to aci, current value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG dnaScope: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaThreshold: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Posix IDs 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG dnaMagicRegen: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG dnaNextValue: 2018-02-15T06:44:10Z DEBUG 1101 2018-02-15T06:44:10Z DEBUG dnaExcludeScope: 2018-02-15T06:44:10Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaFilter: 2018-02-15T06:44:10Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2018-02-15T06:44:10Z DEBUG dnaType: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG dnaMaxValue: 2018-02-15T06:44:10Z DEBUG 1100 2018-02-15T06:44:10Z DEBUG dnaSharedCfgDN: 2018-02-15T06:44:10Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG [(0, u'aci', [u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";)'])] 2018-02-15T06:44:10Z DEBUG Updated 1 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/40-vault.update' 2018-02-15T06:44:10Z DEBUG New entry: cn=vaults,cn=kra,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=vaults,cn=kra,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=pytest,dc=test")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:44:10Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=pytest,dc=test")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=pytest,dc=test")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)' from aci, current value [] 2018-02-15T06:44:10Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=pytest,dc=test")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' from aci, current value [] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' from aci, current value [] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' from aci, current value [] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' from aci, current value [] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' from aci, current value [] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' from aci, current value [] 2018-02-15T06:44:10Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' not in aci 2018-02-15T06:44:10Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test" and userattr="owner#SELFDN";)' from aci, current value [] 2018-02-15T06:44:10Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test" and userattr="owner#SELFDN";)' not in aci 2018-02-15T06:44:10Z DEBUG addifexist: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=pytest,dc=test" and userattr="owner#SELFDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=pytest,dc=test" and userattr="owner#SELFDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=vaults,cn=kra,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/41-caacl.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=caacls,cn=ca,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=caacls,cn=ca,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Add CA ACL";allow (add) groupdn = "ldap:///cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Delete CA ACL";allow (delete) groupdn = "ldap:///cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "hostcategory || ipacacategory || ipacertprofilecategory || ipamemberca || ipamembercertprofile || memberhost || memberservice || memberuser || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Manage CA ACL Membership";allow (write) groupdn = "ldap:///cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipaenabledflag")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Modify CA ACL";allow (write) groupdn = "ldap:///cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipacacategory || ipacertprofilecategory || ipaenabledflag || ipamemberca || ipamembercertprofile || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Read CA ACLs";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG caacls 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=caacls,cn=ca,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Add CA ACL";allow (add) groupdn = "ldap:///cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Delete CA ACL";allow (delete) groupdn = "ldap:///cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "hostcategory || ipacacategory || ipacertprofilecategory || ipamemberca || ipamembercertprofile || memberhost || memberservice || memberuser || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Manage CA ACL Membership";allow (write) groupdn = "ldap:///cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipaenabledflag")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Modify CA ACL";allow (write) groupdn = "ldap:///cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipacacategory || ipacertprofilecategory || ipaenabledflag || ipamemberca || ipamembercertprofile || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Read CA ACLs";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG caacls 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/41-lightweight-cas.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=cas,cn=ca,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=cas,cn=ca,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Add CA";allow (add) groupdn = "ldap:///cn=System: Add CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Delete CA";allow (delete) groupdn = "ldap:///cn=System: Delete CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Modify CA";allow (write) groupdn = "ldap:///cn=System: Modify CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacaid || ipacaissuerdn || ipacasubjectdn || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Read CAs";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG cas 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=cas,cn=ca,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Add CA";allow (add) groupdn = "ldap:///cn=System: Add CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Delete CA";allow (delete) groupdn = "ldap:///cn=System: Delete CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Modify CA";allow (write) groupdn = "ldap:///cn=System: Modify CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacaid || ipacaissuerdn || ipacasubjectdn || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Read CAs";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG cas 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/45-roles.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Modify Users and Reset passwords 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Modify Users and Reset passwords 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Modify Users and Reset passwords 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Modify Users and Reset passwords 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Modify Group membership,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Modify Group membership 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Modify Group membership 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Modify Group membership 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Modify Group membership 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add User to default group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Unlock User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Stage User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Responsible for creating Users and Groups 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG User Administrator 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add User to default group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Unlock User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Stage User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Responsible for creating Users and Groups 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG User Administrator 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add User to default group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Unlock User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG User Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG User Administrators 2018-02-15T06:44:10Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add User to default group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Unlock User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG User Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG User Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Group Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Group Administrators 2018-02-15T06:44:10Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Group Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Group Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Stage User Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Stage User Administrators 2018-02-15T06:44:10Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Stage User Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Stage User Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Host Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Service Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Automount Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG IT Specialist 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IT Specialist 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Host Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Service Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Automount Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG IT Specialist 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IT Specialist 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Host Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Host Administrators 2018-02-15T06:44:10Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Host Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Host Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Host Group Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Host Group Administrators 2018-02-15T06:44:10Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Host Group Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Host Group Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Service Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Service Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Service Administrators 2018-02-15T06:44:10Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Service Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Service Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Automount Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Automount Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Automount Administrators 2018-02-15T06:44:10Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Automount Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Automount Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=HBAC Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Sudo Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG IT Security Specialist 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IT Security Specialist 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=HBAC Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Sudo Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG IT Security Specialist 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IT Security Specialist 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Netgroups Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Netgroups Administrators 2018-02-15T06:44:10Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Netgroups Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Netgroups Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG HBAC Administrator 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG HBAC Administrator 2018-02-15T06:44:10Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG HBAC Administrator 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG HBAC Administrator 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Sudo Administrator 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Sudo Administrator 2018-02-15T06:44:10Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Sudo Administrator 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Sudo Administrator 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Delegation Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Security Architect 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Security Architect 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Delegation Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Security Architect 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Security Architect 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Role administration 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Delegation Administrator 2018-02-15T06:44:10Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Remove Roles,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Role administration 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Delegation Administrator 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Replication Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Replication Administrators 2018-02-15T06:44:10Z DEBUG add: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test', u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test', u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test', u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test', u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test', u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test', u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test', u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test', u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Replication Administrators 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Replication Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Write IPA Configuration 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Write IPA Configuration 2018-02-15T06:44:10Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Write IPA Configuration 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Write IPA Configuration 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Password Policy Administrator 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Password Policy Administrator 2018-02-15T06:44:10Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test' to member, current value [u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Password Policy Administrator 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Password Policy Administrator 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/50-7_bit_check.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:10Z DEBUG NS7bitAttr 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG 7-bit check 2018-02-15T06:44:10Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:10Z DEBUG 1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:10Z DEBUG NS7bitAttr_Init 2018-02-15T06:44:10Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:10Z DEBUG Enforce 7-bit clean attribute values 2018-02-15T06:44:10Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:10Z DEBUG libattr-unique-plugin 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginarg0: 2018-02-15T06:44:10Z DEBUG uid 2018-02-15T06:44:10Z DEBUG nsslapd-pluginarg3: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-pluginarg2: 2018-02-15T06:44:10Z DEBUG , 2018-02-15T06:44:10Z DEBUG nsslapd-pluginarg1: 2018-02-15T06:44:10Z DEBUG mail 2018-02-15T06:44:10Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:10Z DEBUG betxnpreoperation 2018-02-15T06:44:10Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:10Z DEBUG 389 Project 2018-02-15T06:44:10Z DEBUG replace: userpassword not found, skipping 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:10Z DEBUG NS7bitAttr 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG 7-bit check 2018-02-15T06:44:10Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:10Z DEBUG 1.3.7.5 2018-02-15T06:44:10Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:10Z DEBUG NS7bitAttr_Init 2018-02-15T06:44:10Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:10Z DEBUG Enforce 7-bit clean attribute values 2018-02-15T06:44:10Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:10Z DEBUG libattr-unique-plugin 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginarg0: 2018-02-15T06:44:10Z DEBUG uid 2018-02-15T06:44:10Z DEBUG nsslapd-pluginarg3: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-pluginarg2: 2018-02-15T06:44:10Z DEBUG , 2018-02-15T06:44:10Z DEBUG nsslapd-pluginarg1: 2018-02-15T06:44:10Z DEBUG mail 2018-02-15T06:44:10Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:10Z DEBUG betxnpreoperation 2018-02-15T06:44:10Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:10Z DEBUG 389 Project 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/50-dogtag10-migration.update' 2018-02-15T06:44:10Z DEBUG New entry: cn=aclResources,o=ipaca 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=aclResources,o=ipaca 2018-02-15T06:44:10Z DEBUG addifexist: 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout' to resourceACLS, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations' to resourceACLS, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations' to resourceACLS, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations' to resourceACLS, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations' to resourceACLS, current value [] 2018-02-15T06:44:10Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group":Anybody is allowed to read domain.xml but only Subsystem group is allowed to modify the domain.xml not found, skipping 2018-02-15T06:44:10Z DEBUG replace: certServer.ca.connectorInfo:read,modify:allow (modify,read) group="Enterprise KRA Administrators":Only Enterprise Administrators are allowed to update the connector information not found, skipping 2018-02-15T06:44:10Z DEBUG addifexist: 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles' to resourceACLS, current value [] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=aclResources,o=ipaca 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/50-externalmembers.update' 2018-02-15T06:44:10Z DEBUG New entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG addifexist: 'ipaexternalmember=%deref_r("member","ipaexternalmember")' to schema-compat-entry-attribute, current value [] 2018-02-15T06:44:10Z DEBUG addifexist: 'objectclass=ipaexternalgroup' to schema-compat-entry-attribute, current value [] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/50-groupuuid.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG admins 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG posixgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG nestedGroup 2018-02-15T06:44:10Z DEBUG ipaNTGroupAttrs 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipaNTSecurityIdentifier: 2018-02-15T06:44:10Z DEBUG S-1-5-21-2367860149-4019230202-3128766626-512 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG uid=admin,cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG gidNumber: 2018-02-15T06:44:10Z DEBUG 936000000 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG c3a48082-1149-11e8-a347-0050455f413d 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Account administrators group 2018-02-15T06:44:10Z DEBUG add: 'ipaobject' to objectclass, current value [u'top', u'groupofnames', u'posixgroup', u'ipausergroup', u'ipaobject', u'nestedGroup', u'ipaNTGroupAttrs'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'groupofnames', u'posixgroup', u'ipausergroup', u'nestedGroup', u'ipaNTGroupAttrs', u'ipaobject'] 2018-02-15T06:44:10Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value [u'c3a48082-1149-11e8-a347-0050455f413d'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG admins 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG posixgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG nestedGroup 2018-02-15T06:44:10Z DEBUG ipaNTGroupAttrs 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipaNTSecurityIdentifier: 2018-02-15T06:44:10Z DEBUG S-1-5-21-2367860149-4019230202-3128766626-512 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG uid=admin,cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG gidNumber: 2018-02-15T06:44:10Z DEBUG 936000000 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG c3a48082-1149-11e8-a347-0050455f413d 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Account administrators group 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=ipausers,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipausers 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Default group for all users 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG c3c32ffa-1149-11e8-a8c8-0050455f413d 2018-02-15T06:44:10Z DEBUG add: 'ipaobject' to objectclass, current value [u'top', u'groupofnames', u'nestedgroup', u'ipausergroup', u'ipaobject'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'groupofnames', u'nestedgroup', u'ipausergroup', u'ipaobject'] 2018-02-15T06:44:10Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value [u'c3c32ffa-1149-11e8-a8c8-0050455f413d'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipausers 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Default group for all users 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG c3c32ffa-1149-11e8-a8c8-0050455f413d 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=editors,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG posixgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG nestedGroup 2018-02-15T06:44:10Z DEBUG gidNumber: 2018-02-15T06:44:10Z DEBUG 936000002 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG editors 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Limited admins who can edit other users 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG c3c5738c-1149-11e8-be2f-0050455f413d 2018-02-15T06:44:10Z DEBUG add: 'ipaobject' to objectclass, current value [u'top', u'groupofnames', u'posixgroup', u'ipausergroup', u'ipaobject', u'nestedGroup'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'groupofnames', u'posixgroup', u'ipausergroup', u'nestedGroup', u'ipaobject'] 2018-02-15T06:44:10Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value [u'c3c5738c-1149-11e8-be2f-0050455f413d'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG posixgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG nestedGroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG gidNumber: 2018-02-15T06:44:10Z DEBUG 936000002 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG editors 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Limited admins who can edit other users 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG c3c5738c-1149-11e8-be2f-0050455f413d 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/50-hbacservice.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=crond,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG crond 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG crond 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4ea6f38-114a-11e8-bd0c-0050455f413d 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG crond 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG crond 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4ea6f38-114a-11e8-bd0c-0050455f413d 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=vsftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG vsftpd 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG vsftpd 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4edaa68-114a-11e8-ad69-0050455f413d 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG vsftpd 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG vsftpd 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4edaa68-114a-11e8-ad69-0050455f413d 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=proftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG proftpd 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG proftpd 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4f150fa-114a-11e8-87aa-0050455f413d 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG proftpd 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG proftpd 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4f150fa-114a-11e8-87aa-0050455f413d 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG pure-ftpd 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG pure-ftpd 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4f5e3b8-114a-11e8-8496-0050455f413d 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG pure-ftpd 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG pure-ftpd 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4f5e3b8-114a-11e8-8496-0050455f413d 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=gssftp,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG gssftp 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG gssftp 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4fa6726-114a-11e8-9f2e-0050455f413d 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipahbacservice 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG gssftp 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG gssftp 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4fa6726-114a-11e8-9f2e-0050455f413d 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipahbacservicegroup 2018-02-15T06:44:10Z DEBUG nestedGroup 2018-02-15T06:44:10Z DEBUG groupOfNames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Default group of ftp related services 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ftp 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4fdbc5a-114a-11e8-b4ea-0050455f413d 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipahbacservicegroup 2018-02-15T06:44:10Z DEBUG nestedGroup 2018-02-15T06:44:10Z DEBUG groupOfNames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Default group of ftp related services 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ftp 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b4fdbc5a-114a-11e8-b4ea-0050455f413d 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/50-ipaconfig.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ipaConfig,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipaDefaultLoginShell: 2018-02-15T06:44:10Z DEBUG /bin/sh 2018-02-15T06:44:10Z DEBUG ipaCertificateSubjectBase: 2018-02-15T06:44:10Z DEBUG O=PYTEST.TEST 2018-02-15T06:44:10Z DEBUG ipaDefaultEmailDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipaConfig 2018-02-15T06:44:10Z DEBUG ipaSELinuxUserMapDefault: 2018-02-15T06:44:10Z DEBUG unconfined_u:s0-s0:c0.c1023 2018-02-15T06:44:10Z DEBUG ipaUserObjectClasses: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG person 2018-02-15T06:44:10Z DEBUG organizationalperson 2018-02-15T06:44:10Z DEBUG inetorgperson 2018-02-15T06:44:10Z DEBUG inetuser 2018-02-15T06:44:10Z DEBUG posixaccount 2018-02-15T06:44:10Z DEBUG krbprincipalaux 2018-02-15T06:44:10Z DEBUG krbticketpolicyaux 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipasshuser 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG ipaKrbAuthzData: 2018-02-15T06:44:10Z DEBUG MS-PAC 2018-02-15T06:44:10Z DEBUG nfs:NONE 2018-02-15T06:44:10Z DEBUG ipaDefaultPrimaryGroup: 2018-02-15T06:44:10Z DEBUG ipausers 2018-02-15T06:44:10Z DEBUG ipaPwdExpAdvNotify: 2018-02-15T06:44:10Z DEBUG 4 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaGuiConfig 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaUserAuthTypeClass 2018-02-15T06:44:10Z DEBUG ipaNameResolutionData 2018-02-15T06:44:10Z DEBUG ipaGroupSearchFields: 2018-02-15T06:44:10Z DEBUG cn,description 2018-02-15T06:44:10Z DEBUG ipaMigrationEnabled: 2018-02-15T06:44:10Z DEBUG FALSE 2018-02-15T06:44:10Z DEBUG ipaHomesRootDir: 2018-02-15T06:44:10Z DEBUG /home 2018-02-15T06:44:10Z DEBUG ipaSearchTimeLimit: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG ipaGroupObjectClasses: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG AllowNThash 2018-02-15T06:44:10Z DEBUG KDC:Disable Last Success 2018-02-15T06:44:10Z DEBUG ipaSELinuxUserMapOrder: 2018-02-15T06:44:10Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2018-02-15T06:44:10Z DEBUG ipaSearchRecordsLimit: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG ipaMaxUsernameLength: 2018-02-15T06:44:10Z DEBUG 32 2018-02-15T06:44:10Z DEBUG ipaUserSearchFields: 2018-02-15T06:44:10Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2018-02-15T06:44:10Z DEBUG add: 'guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023' to ipaSELinuxUserMapOrder, current value [u'guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023'] 2018-02-15T06:44:10Z DEBUG add: 'unconfined_u:s0-s0:c0.c1023' to ipaSELinuxUserMapDefault, current value [u'unconfined_u:s0-s0:c0.c1023'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'unconfined_u:s0-s0:c0.c1023'] 2018-02-15T06:44:10Z DEBUG add: 'ipasshuser' to ipaUserObjectClasses, current value [u'top', u'person', u'organizationalperson', u'inetorgperson', u'inetuser', u'posixaccount', u'krbprincipalaux', u'krbticketpolicyaux', u'ipaobject', u'ipasshuser'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'person', u'organizationalperson', u'inetorgperson', u'inetuser', u'posixaccount', u'krbprincipalaux', u'krbticketpolicyaux', u'ipaobject', u'ipasshuser'] 2018-02-15T06:44:10Z DEBUG remove: 'AllowLMhash' from ipaConfigString, current value [u'AllowNThash', u'KDC:Disable Last Success'] 2018-02-15T06:44:10Z DEBUG remove: 'AllowLMhash' not in ipaConfigString 2018-02-15T06:44:10Z DEBUG add: 'ipaUserAuthTypeClass' to objectClass, current value [u'nsContainer', u'top', u'ipaGuiConfig', u'ipaConfigObject', u'ipaUserAuthTypeClass', u'ipaNameResolutionData'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'nsContainer', u'top', u'ipaGuiConfig', u'ipaConfigObject', u'ipaNameResolutionData', u'ipaUserAuthTypeClass'] 2018-02-15T06:44:10Z DEBUG add: 'ipaNameResolutionData' to objectClass, current value [u'nsContainer', u'top', u'ipaGuiConfig', u'ipaConfigObject', u'ipaNameResolutionData', u'ipaUserAuthTypeClass'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'nsContainer', u'top', u'ipaGuiConfig', u'ipaConfigObject', u'ipaUserAuthTypeClass', u'ipaNameResolutionData'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ipaConfig,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipaDefaultLoginShell: 2018-02-15T06:44:10Z DEBUG /bin/sh 2018-02-15T06:44:10Z DEBUG ipaCertificateSubjectBase: 2018-02-15T06:44:10Z DEBUG O=PYTEST.TEST 2018-02-15T06:44:10Z DEBUG ipaDefaultEmailDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipaConfig 2018-02-15T06:44:10Z DEBUG ipaSELinuxUserMapDefault: 2018-02-15T06:44:10Z DEBUG unconfined_u:s0-s0:c0.c1023 2018-02-15T06:44:10Z DEBUG ipaUserObjectClasses: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG person 2018-02-15T06:44:10Z DEBUG organizationalperson 2018-02-15T06:44:10Z DEBUG inetorgperson 2018-02-15T06:44:10Z DEBUG inetuser 2018-02-15T06:44:10Z DEBUG posixaccount 2018-02-15T06:44:10Z DEBUG krbprincipalaux 2018-02-15T06:44:10Z DEBUG krbticketpolicyaux 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipasshuser 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG ipaKrbAuthzData: 2018-02-15T06:44:10Z DEBUG MS-PAC 2018-02-15T06:44:10Z DEBUG nfs:NONE 2018-02-15T06:44:10Z DEBUG ipaDefaultPrimaryGroup: 2018-02-15T06:44:10Z DEBUG ipausers 2018-02-15T06:44:10Z DEBUG ipaPwdExpAdvNotify: 2018-02-15T06:44:10Z DEBUG 4 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaGuiConfig 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaUserAuthTypeClass 2018-02-15T06:44:10Z DEBUG ipaNameResolutionData 2018-02-15T06:44:10Z DEBUG ipaGroupSearchFields: 2018-02-15T06:44:10Z DEBUG cn,description 2018-02-15T06:44:10Z DEBUG ipaMigrationEnabled: 2018-02-15T06:44:10Z DEBUG FALSE 2018-02-15T06:44:10Z DEBUG ipaHomesRootDir: 2018-02-15T06:44:10Z DEBUG /home 2018-02-15T06:44:10Z DEBUG ipaSearchTimeLimit: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG ipaGroupObjectClasses: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG AllowNThash 2018-02-15T06:44:10Z DEBUG KDC:Disable Last Success 2018-02-15T06:44:10Z DEBUG ipaSELinuxUserMapOrder: 2018-02-15T06:44:10Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2018-02-15T06:44:10Z DEBUG ipaSearchRecordsLimit: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG ipaMaxUsernameLength: 2018-02-15T06:44:10Z DEBUG 32 2018-02-15T06:44:10Z DEBUG ipaUserSearchFields: 2018-02-15T06:44:10Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/50-krbenctypes.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbSubTrees: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG PYTEST.TEST 2018-02-15T06:44:10Z DEBUG krbDefaultEncSaltTypes: 2018-02-15T06:44:10Z DEBUG aes256-cts:special 2018-02-15T06:44:10Z DEBUG aes128-cts:special 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG krbrealmcontainer 2018-02-15T06:44:10Z DEBUG krbticketpolicyaux 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticketlife || krbsupportedencsalttypes || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read Default Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Add Group Password Policy";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Delete Group Password Policy";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Modify Group Password Policy";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || cospriority || createtimestamp || entryusn || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Read Group Password Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG krbSearchScope: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG krbSupportedEncSaltTypes: 2018-02-15T06:44:10Z DEBUG aes256-cts:normal 2018-02-15T06:44:10Z DEBUG aes256-cts:special 2018-02-15T06:44:10Z DEBUG aes128-cts:normal 2018-02-15T06:44:10Z DEBUG aes128-cts:special 2018-02-15T06:44:10Z DEBUG des3-hmac-sha1:normal 2018-02-15T06:44:10Z DEBUG des3-hmac-sha1:special 2018-02-15T06:44:10Z DEBUG arcfour-hmac:normal 2018-02-15T06:44:10Z DEBUG arcfour-hmac:special 2018-02-15T06:44:10Z DEBUG camellia128-cts-cmac:normal 2018-02-15T06:44:10Z DEBUG camellia128-cts-cmac:special 2018-02-15T06:44:10Z DEBUG camellia256-cts-cmac:normal 2018-02-15T06:44:10Z DEBUG camellia256-cts-cmac:special 2018-02-15T06:44:10Z DEBUG krbMaxTicketLife: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG krbMKey: 2018-02-15T06:44:10Z DEBUG XXXXXXXX 2018-02-15T06:44:10Z DEBUG krbPwdPolicyReference: 2018-02-15T06:44:10Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbMaxRenewableAge: 2018-02-15T06:44:10Z DEBUG 604800 2018-02-15T06:44:10Z DEBUG add: 'camellia128-cts-cmac:normal' to krbSupportedEncSaltTypes, current value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal'] 2018-02-15T06:44:10Z DEBUG add: 'camellia128-cts-cmac:special' to krbSupportedEncSaltTypes, current value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special'] 2018-02-15T06:44:10Z DEBUG add: 'camellia256-cts-cmac:normal' to krbSupportedEncSaltTypes, current value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal'] 2018-02-15T06:44:10Z DEBUG add: 'camellia256-cts-cmac:special' to krbSupportedEncSaltTypes, current value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbSubTrees: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG PYTEST.TEST 2018-02-15T06:44:10Z DEBUG krbDefaultEncSaltTypes: 2018-02-15T06:44:10Z DEBUG aes256-cts:special 2018-02-15T06:44:10Z DEBUG aes128-cts:special 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG krbrealmcontainer 2018-02-15T06:44:10Z DEBUG krbticketpolicyaux 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticketlife || krbsupportedencsalttypes || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read Default Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Add Group Password Policy";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Delete Group Password Policy";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Modify Group Password Policy";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || cospriority || createtimestamp || entryusn || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Read Group Password Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG krbSearchScope: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG krbSupportedEncSaltTypes: 2018-02-15T06:44:10Z DEBUG aes256-cts:normal 2018-02-15T06:44:10Z DEBUG aes256-cts:special 2018-02-15T06:44:10Z DEBUG aes128-cts:normal 2018-02-15T06:44:10Z DEBUG aes128-cts:special 2018-02-15T06:44:10Z DEBUG des3-hmac-sha1:normal 2018-02-15T06:44:10Z DEBUG des3-hmac-sha1:special 2018-02-15T06:44:10Z DEBUG arcfour-hmac:normal 2018-02-15T06:44:10Z DEBUG arcfour-hmac:special 2018-02-15T06:44:10Z DEBUG camellia128-cts-cmac:normal 2018-02-15T06:44:10Z DEBUG camellia128-cts-cmac:special 2018-02-15T06:44:10Z DEBUG camellia256-cts-cmac:normal 2018-02-15T06:44:10Z DEBUG camellia256-cts-cmac:special 2018-02-15T06:44:10Z DEBUG krbMaxTicketLife: 2018-02-15T06:44:10Z DEBUG 86400 2018-02-15T06:44:10Z DEBUG krbMKey: 2018-02-15T06:44:10Z DEBUG XXXXXXXX 2018-02-15T06:44:10Z DEBUG krbPwdPolicyReference: 2018-02-15T06:44:10Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=PYTEST.TEST,cn=kerberos,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG krbMaxRenewableAge: 2018-02-15T06:44:10Z DEBUG 604800 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/50-nis.update' 2018-02-15T06:44:10Z DEBUG Executing upgrade plugin: update_nis_configuration 2018-02-15T06:44:10Z DEBUG raw: update_nis_configuration 2018-02-15T06:44:10Z DEBUG Skipping NIS update, NIS Server is not configured 2018-02-15T06:44:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:10Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/55-pbacmemberof.update' 2018-02-15T06:44:10Z DEBUG New entry: cn=Update PBAC memberOf 137379698,cn=memberof task,cn=tasks,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Update PBAC memberOf 137379698,cn=memberof task,cn=tasks,cn=config 2018-02-15T06:44:10Z DEBUG add: 'top' to objectClass, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top'] 2018-02-15T06:44:10Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'extensibleObject'] 2018-02-15T06:44:10Z DEBUG add: 'IPA PBAC memberOf 137379698' to cn, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'IPA PBAC memberOf 137379698'] 2018-02-15T06:44:10Z DEBUG add: 'cn=privileges,cn=pbac,dc=pytest,dc=test' to basedn, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=privileges,cn=pbac,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: '(objectclass=*)' to filter, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(objectclass=*)'] 2018-02-15T06:44:10Z DEBUG add: '10' to ttl, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'10'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Update PBAC memberOf 137379698,cn=memberof task,cn=tasks,cn=config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG filter: 2018-02-15T06:44:10Z DEBUG (objectclass=*) 2018-02-15T06:44:10Z DEBUG basedn: 2018-02-15T06:44:10Z DEBUG cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA PBAC memberOf 137379698 2018-02-15T06:44:10Z DEBUG ttl: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG New entry: cn=Update Role memberOf 137379698,cn=memberof task,cn=tasks,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Update Role memberOf 137379698,cn=memberof task,cn=tasks,cn=config 2018-02-15T06:44:10Z DEBUG add: 'top' to objectClass, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top'] 2018-02-15T06:44:10Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'extensibleObject'] 2018-02-15T06:44:10Z DEBUG add: 'Update Role memberOf 137379698' to cn, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'Update Role memberOf 137379698'] 2018-02-15T06:44:10Z DEBUG add: 'cn=roles,cn=accounts,dc=pytest,dc=test' to basedn, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=roles,cn=accounts,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: '(objectclass=*)' to filter, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(objectclass=*)'] 2018-02-15T06:44:10Z DEBUG add: '10' to ttl, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'10'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Update Role memberOf 137379698,cn=memberof task,cn=tasks,cn=config 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG filter: 2018-02-15T06:44:10Z DEBUG (objectclass=*) 2018-02-15T06:44:10Z DEBUG basedn: 2018-02-15T06:44:10Z DEBUG cn=roles,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Update Role memberOf 137379698 2018-02-15T06:44:10Z DEBUG ttl: 2018-02-15T06:44:10Z DEBUG 10 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/59-trusts-sysacount.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG GroupOfNames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ADTrust Agents,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG krbprincipalname=cifs/master.pytest.test@pytest.test,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG fqdn=master.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG adtrust agents 2018-02-15T06:44:10Z DEBUG add: 'nestedgroup' to objectClass, current value [u'GroupOfNames', u'top', u'nestedgroup'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'GroupOfNames', u'top', u'nestedgroup'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG GroupOfNames 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=ADTrust Agents,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG krbprincipalname=cifs/master.pytest.test@pytest.test,cn=services,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG fqdn=master.pytest.test,cn=computers,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG adtrust agents 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/60-trusts.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG uid=admin,cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Trusts administrators group 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG trust admins 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b5266e70-114a-11e8-8475-0050455f413d 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG uid=admin,cn=users,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Trusts administrators group 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG trust admins 2018-02-15T06:44:10Z DEBUG ipaUniqueID: 2018-02-15T06:44:10Z DEBUG b5266e70-114a-11e8-8475-0050455f413d 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG System accounts able to access trust information 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ADTrust Agents 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG member: 2018-02-15T06:44:10Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG System accounts able to access trust information 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ADTrust Agents 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=trusts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=trusts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG trusts 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=trusts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG trusts 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=trusts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=trusts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG trusts 2018-02-15T06:44:10Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)' to aci, current value [u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: '(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)' to aci, current value [u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG replace: updated value [u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG replace: (target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";) not found, skipping 2018-02-15T06:44:10Z DEBUG add: '(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)' to aci, current value [u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=trusts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=trusts,dc=pytest,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG trusts 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG info: 2018-02-15T06:44:10Z DEBUG IPA V2.0 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG domain 2018-02-15T06:44:10Z DEBUG pilotObject 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nisDomainObject 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG dc: 2018-02-15T06:44:10Z DEBUG pytest 2018-02-15T06:44:10Z DEBUG nisDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG add: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)'] 2018-02-15T06:44:10Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)' not in aci 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG info: 2018-02-15T06:44:10Z DEBUG IPA V2.0 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG domain 2018-02-15T06:44:10Z DEBUG pilotObject 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nisDomainObject 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG dc: 2018-02-15T06:44:10Z DEBUG pytest 2018-02-15T06:44:10Z DEBUG nisDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ipaConfig,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipaDefaultLoginShell: 2018-02-15T06:44:10Z DEBUG /bin/sh 2018-02-15T06:44:10Z DEBUG ipaCertificateSubjectBase: 2018-02-15T06:44:10Z DEBUG O=PYTEST.TEST 2018-02-15T06:44:10Z DEBUG ipaDefaultEmailDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipaConfig 2018-02-15T06:44:10Z DEBUG ipaSELinuxUserMapDefault: 2018-02-15T06:44:10Z DEBUG unconfined_u:s0-s0:c0.c1023 2018-02-15T06:44:10Z DEBUG ipaUserObjectClasses: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG person 2018-02-15T06:44:10Z DEBUG organizationalperson 2018-02-15T06:44:10Z DEBUG inetorgperson 2018-02-15T06:44:10Z DEBUG inetuser 2018-02-15T06:44:10Z DEBUG posixaccount 2018-02-15T06:44:10Z DEBUG krbprincipalaux 2018-02-15T06:44:10Z DEBUG krbticketpolicyaux 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipasshuser 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG ipaKrbAuthzData: 2018-02-15T06:44:10Z DEBUG MS-PAC 2018-02-15T06:44:10Z DEBUG nfs:NONE 2018-02-15T06:44:10Z DEBUG ipaDefaultPrimaryGroup: 2018-02-15T06:44:10Z DEBUG ipausers 2018-02-15T06:44:10Z DEBUG ipaPwdExpAdvNotify: 2018-02-15T06:44:10Z DEBUG 4 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaGuiConfig 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaUserAuthTypeClass 2018-02-15T06:44:10Z DEBUG ipaNameResolutionData 2018-02-15T06:44:10Z DEBUG ipaGroupSearchFields: 2018-02-15T06:44:10Z DEBUG cn,description 2018-02-15T06:44:10Z DEBUG ipaMigrationEnabled: 2018-02-15T06:44:10Z DEBUG FALSE 2018-02-15T06:44:10Z DEBUG ipaHomesRootDir: 2018-02-15T06:44:10Z DEBUG /home 2018-02-15T06:44:10Z DEBUG ipaSearchTimeLimit: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG ipaGroupObjectClasses: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG AllowNThash 2018-02-15T06:44:10Z DEBUG KDC:Disable Last Success 2018-02-15T06:44:10Z DEBUG ipaSELinuxUserMapOrder: 2018-02-15T06:44:10Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2018-02-15T06:44:10Z DEBUG ipaSearchRecordsLimit: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG ipaMaxUsernameLength: 2018-02-15T06:44:10Z DEBUG 32 2018-02-15T06:44:10Z DEBUG ipaUserSearchFields: 2018-02-15T06:44:10Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2018-02-15T06:44:10Z DEBUG addifnew: 'MS-PAC' to ipaKrbAuthzData, current value [u'MS-PAC', u'nfs:NONE'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ipaConfig,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipaDefaultLoginShell: 2018-02-15T06:44:10Z DEBUG /bin/sh 2018-02-15T06:44:10Z DEBUG ipaCertificateSubjectBase: 2018-02-15T06:44:10Z DEBUG O=PYTEST.TEST 2018-02-15T06:44:10Z DEBUG ipaDefaultEmailDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipaConfig 2018-02-15T06:44:10Z DEBUG ipaSELinuxUserMapDefault: 2018-02-15T06:44:10Z DEBUG unconfined_u:s0-s0:c0.c1023 2018-02-15T06:44:10Z DEBUG ipaUserObjectClasses: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG person 2018-02-15T06:44:10Z DEBUG organizationalperson 2018-02-15T06:44:10Z DEBUG inetorgperson 2018-02-15T06:44:10Z DEBUG inetuser 2018-02-15T06:44:10Z DEBUG posixaccount 2018-02-15T06:44:10Z DEBUG krbprincipalaux 2018-02-15T06:44:10Z DEBUG krbticketpolicyaux 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipasshuser 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG ipaKrbAuthzData: 2018-02-15T06:44:10Z DEBUG MS-PAC 2018-02-15T06:44:10Z DEBUG nfs:NONE 2018-02-15T06:44:10Z DEBUG ipaDefaultPrimaryGroup: 2018-02-15T06:44:10Z DEBUG ipausers 2018-02-15T06:44:10Z DEBUG ipaPwdExpAdvNotify: 2018-02-15T06:44:10Z DEBUG 4 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaGuiConfig 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaUserAuthTypeClass 2018-02-15T06:44:10Z DEBUG ipaNameResolutionData 2018-02-15T06:44:10Z DEBUG ipaGroupSearchFields: 2018-02-15T06:44:10Z DEBUG cn,description 2018-02-15T06:44:10Z DEBUG ipaMigrationEnabled: 2018-02-15T06:44:10Z DEBUG FALSE 2018-02-15T06:44:10Z DEBUG ipaHomesRootDir: 2018-02-15T06:44:10Z DEBUG /home 2018-02-15T06:44:10Z DEBUG ipaSearchTimeLimit: 2018-02-15T06:44:10Z DEBUG 2 2018-02-15T06:44:10Z DEBUG ipaGroupObjectClasses: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG ipausergroup 2018-02-15T06:44:10Z DEBUG ipaobject 2018-02-15T06:44:10Z DEBUG ipaConfigString: 2018-02-15T06:44:10Z DEBUG AllowNThash 2018-02-15T06:44:10Z DEBUG KDC:Disable Last Success 2018-02-15T06:44:10Z DEBUG ipaSELinuxUserMapOrder: 2018-02-15T06:44:10Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2018-02-15T06:44:10Z DEBUG ipaSearchRecordsLimit: 2018-02-15T06:44:10Z DEBUG 100 2018-02-15T06:44:10Z DEBUG ipaMaxUsernameLength: 2018-02-15T06:44:10Z DEBUG 32 2018-02-15T06:44:10Z DEBUG ipaUserSearchFields: 2018-02-15T06:44:10Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/61-trusts-s4u2proxy.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupOfPrincipals 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberPrincipal: 2018-02-15T06:44:10Z DEBUG cifs/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipa-cifs-delegation-targets 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG groupOfPrincipals 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG memberPrincipal: 2018-02-15T06:44:10Z DEBUG cifs/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipa-cifs-delegation-targets 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipaKrb5DelegationACL 2018-02-15T06:44:10Z DEBUG groupOfPrincipals 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaAllowedTarget: 2018-02-15T06:44:10Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberPrincipal: 2018-02-15T06:44:10Z DEBUG HTTP/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:10Z DEBUG HTTP/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:10Z DEBUG HTTP/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipa-http-delegation 2018-02-15T06:44:10Z DEBUG add: 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test' to ipaAllowedTarget, current value [u'cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test', u'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test', u'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG ipaKrb5DelegationACL 2018-02-15T06:44:10Z DEBUG groupOfPrincipals 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG ipaAllowedTarget: 2018-02-15T06:44:10Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG memberPrincipal: 2018-02-15T06:44:10Z DEBUG HTTP/master.pytest.test@PYTEST.TEST 2018-02-15T06:44:10Z DEBUG HTTP/replica.pytest.test@PYTEST.TEST 2018-02-15T06:44:10Z DEBUG HTTP/replica3.pytest.test@PYTEST.TEST 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ipa-http-delegation 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/62-ranges.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ranges,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ranges 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ranges,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ranges 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG New entry: cn=IPA Range-Check,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginid: 2018-02-15T06:44:10Z DEBUG ipa_range_check_version 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA Range-Check 2018-02-15T06:44:10Z DEBUG objectclass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-basedn: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-plugindescription: 2018-02-15T06:44:10Z DEBUG IPA Range-Check plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginenabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginpath: 2018-02-15T06:44:10Z DEBUG libipa_range_check 2018-02-15T06:44:10Z DEBUG nsslapd-pluginversion: 2018-02-15T06:44:10Z DEBUG 1.0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginvendor: 2018-02-15T06:44:10Z DEBUG Red Hat, Inc. 2018-02-15T06:44:10Z DEBUG nsslapd-plugintype: 2018-02-15T06:44:10Z DEBUG preoperation 2018-02-15T06:44:10Z DEBUG nsslapd-plugininitfunc: 2018-02-15T06:44:10Z DEBUG ipa_range_check_init 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginid: 2018-02-15T06:44:10Z DEBUG ipa_range_check_version 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG IPA Range-Check 2018-02-15T06:44:10Z DEBUG objectclass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-basedn: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsslapd-plugindescription: 2018-02-15T06:44:10Z DEBUG IPA Range-Check plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginenabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginpath: 2018-02-15T06:44:10Z DEBUG libipa_range_check 2018-02-15T06:44:10Z DEBUG nsslapd-pluginversion: 2018-02-15T06:44:10Z DEBUG 1.0 2018-02-15T06:44:10Z DEBUG nsslapd-plugin-depends-on-type: 2018-02-15T06:44:10Z DEBUG database 2018-02-15T06:44:10Z DEBUG nsslapd-pluginvendor: 2018-02-15T06:44:10Z DEBUG Red Hat, Inc. 2018-02-15T06:44:10Z DEBUG nsslapd-plugintype: 2018-02-15T06:44:10Z DEBUG preoperation 2018-02-15T06:44:10Z DEBUG nsslapd-plugininitfunc: 2018-02-15T06:44:10Z DEBUG ipa_range_check_init 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG dnaScope: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaThreshold: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Posix IDs 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG dnaMagicRegen: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG dnaNextValue: 2018-02-15T06:44:10Z DEBUG 1101 2018-02-15T06:44:10Z DEBUG dnaExcludeScope: 2018-02-15T06:44:10Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaFilter: 2018-02-15T06:44:10Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2018-02-15T06:44:10Z DEBUG dnaType: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG dnaMaxValue: 2018-02-15T06:44:10Z DEBUG 1100 2018-02-15T06:44:10Z DEBUG dnaSharedCfgDN: 2018-02-15T06:44:10Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG replace: (|(objectclass=posixAccount)(objectClass=posixGroup)) not found, skipping 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG dnaScope: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaThreshold: 2018-02-15T06:44:10Z DEBUG 500 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Posix IDs 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG dnaMagicRegen: 2018-02-15T06:44:10Z DEBUG -1 2018-02-15T06:44:10Z DEBUG dnaNextValue: 2018-02-15T06:44:10Z DEBUG 1101 2018-02-15T06:44:10Z DEBUG dnaExcludeScope: 2018-02-15T06:44:10Z DEBUG cn=provisioning,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG dnaFilter: 2018-02-15T06:44:10Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2018-02-15T06:44:10Z DEBUG dnaType: 2018-02-15T06:44:10Z DEBUG uidNumber 2018-02-15T06:44:10Z DEBUG gidNumber 2018-02-15T06:44:10Z DEBUG dnaMaxValue: 2018-02-15T06:44:10Z DEBUG 1100 2018-02-15T06:44:10Z DEBUG dnaSharedCfgDN: 2018-02-15T06:44:10Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews-sasl-mapping.update' 2018-02-15T06:44:10Z DEBUG New entry: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2018-02-15T06:44:10Z DEBUG nsSaslMapPriority: 2018-02-15T06:44:10Z DEBUG 20 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ID Overridden Principal 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSaslMapping 2018-02-15T06:44:10Z DEBUG nsSaslMapRegexString: 2018-02-15T06:44:10Z DEBUG \(.*\)@\(.*\) 2018-02-15T06:44:10Z DEBUG nsSaslMapBaseDNTemplate: 2018-02-15T06:44:10Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsSaslMapFilterTemplate: 2018-02-15T06:44:10Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2018-02-15T06:44:10Z DEBUG nsSaslMapPriority: 2018-02-15T06:44:10Z DEBUG 20 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ID Overridden Principal 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSaslMapping 2018-02-15T06:44:10Z DEBUG nsSaslMapRegexString: 2018-02-15T06:44:10Z DEBUG \(.*\)@\(.*\) 2018-02-15T06:44:10Z DEBUG nsSaslMapBaseDNTemplate: 2018-02-15T06:44:10Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG nsSaslMapFilterTemplate: 2018-02-15T06:44:10Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=views,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=views,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || description || entryusn || gecos || gidnumber || homedirectory || ipaanchoruuid || ipaoriginaluid || ipasshpubkey || loginshell || modifytimestamp || objectclass || uid || uidnumber || usercertificate")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipadomainresolutionorder || modifytimestamp || objectclass")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Read ID Views";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG views 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=views,cn=accounts,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || description || entryusn || gecos || gidnumber || homedirectory || ipaanchoruuid || ipaoriginaluid || ipasshpubkey || loginshell || modifytimestamp || objectclass || uid || uidnumber || usercertificate")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipadomainresolutionorder || modifytimestamp || objectclass")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Read ID Views";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG views 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/72-domainlevels.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Domain Level,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipaDomainLevel: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaDomainLevelConfig 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || ipadomainlevel || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipadomainlevelconfig)")(version 3.0;acl "permission:System: Read Domain Level";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Domain Level 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG ipaDomainLevel: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaDomainLevelConfig 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || ipadomainlevel || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipadomainlevelconfig)")(version 3.0;acl "permission:System: Read Domain Level";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Domain Level 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=replica3.pytest.test,cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=replica3.pytest.test,cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaReplTopoManagedServer 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaSupportedDomainLevelConfig 2018-02-15T06:44:10Z DEBUG ipaMaxDomainLevel: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG ipaMinDomainLevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG ipaReplTopoManagedSuffix: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG add: 'ipaConfigObject' to objectClass, current value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaSupportedDomainLevelConfig', u'ipaConfigObject'] 2018-02-15T06:44:10Z DEBUG add: 'ipaSupportedDomainLevelConfig' to objectClass, current value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaSupportedDomainLevelConfig', u'ipaConfigObject'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig'] 2018-02-15T06:44:10Z DEBUG only: set ipaMinDomainLevel to '0', current value [u'0'] 2018-02-15T06:44:10Z DEBUG only: updated value [u'0'] 2018-02-15T06:44:10Z DEBUG only: set ipaMaxDomainLevel to '1', current value [u'1'] 2018-02-15T06:44:10Z DEBUG only: updated value [u'1'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=replica3.pytest.test,cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaReplTopoManagedServer 2018-02-15T06:44:10Z DEBUG ipaConfigObject 2018-02-15T06:44:10Z DEBUG ipaSupportedDomainLevelConfig 2018-02-15T06:44:10Z DEBUG ipaMaxDomainLevel: 2018-02-15T06:44:10Z DEBUG 1 2018-02-15T06:44:10Z DEBUG ipaMinDomainLevel: 2018-02-15T06:44:10Z DEBUG 0 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG replica3.pytest.test 2018-02-15T06:44:10Z DEBUG ipaReplTopoManagedSuffix: 2018-02-15T06:44:10Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/73-certmap.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=certmap,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=certmap,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaCertMapConfigObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Modify Certmap Configuration";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Read Certmap Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG ipaCertMapPromptUsername: 2018-02-15T06:44:10Z DEBUG FALSE 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG certmap 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=certmap,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG ipaCertMapConfigObject 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Modify Certmap Configuration";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Read Certmap Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG ipaCertMapPromptUsername: 2018-02-15T06:44:10Z DEBUG FALSE 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG certmap 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=certmaprules,cn=certmap,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=certmaprules,cn=certmap,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Add Certmap Rules";allow (add) groupdn = "ldap:///cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Delete Certmap Rules";allow (delete) groupdn = "ldap:///cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "associateddomain || cn || description || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Modify Certmap Rules";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "associateddomain || cn || createtimestamp || description || entryusn || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Read Certmap Rules";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG certmaprules 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=certmaprules,cn=certmap,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Add Certmap Rules";allow (add) groupdn = "ldap:///cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Delete Certmap Rules";allow (delete) groupdn = "ldap:///cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "associateddomain || cn || description || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Modify Certmap Rules";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "associateddomain || cn || createtimestamp || description || entryusn || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Read Certmap Rules";allow (compare,read,search) userdn = "ldap:///all";) 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG certmaprules 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Certificate Identity Mapping Administrators 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Certificate Identity Mapping Administrators 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG groupofnames 2018-02-15T06:44:10Z DEBUG nestedgroup 2018-02-15T06:44:10Z DEBUG memberOf: 2018-02-15T06:44:10Z DEBUG cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG description: 2018-02-15T06:44:10Z DEBUG Certificate Identity Mapping Administrators 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Certificate Identity Mapping Administrators 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG info: 2018-02-15T06:44:10Z DEBUG IPA V2.0 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG domain 2018-02-15T06:44:10Z DEBUG pilotObject 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nisDomainObject 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG dc: 2018-02-15T06:44:10Z DEBUG pytest 2018-02-15T06:44:10Z DEBUG nisDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG add: '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";)', u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG info: 2018-02-15T06:44:10Z DEBUG IPA V2.0 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG domain 2018-02-15T06:44:10Z DEBUG pilotObject 2018-02-15T06:44:10Z DEBUG domainRelatedObject 2018-02-15T06:44:10Z DEBUG nisDomainObject 2018-02-15T06:44:10Z DEBUG associatedDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG dc: 2018-02-15T06:44:10Z DEBUG pytest 2018-02-15T06:44:10Z DEBUG nisDomain: 2018-02-15T06:44:10Z DEBUG pytest.test 2018-02-15T06:44:10Z DEBUG aci: 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=pytest,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=pytest,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=pytest,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=pytest,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=pytest,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=pytest,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=pytest,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=pytest,dc=test";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=pytest,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2018-02-15T06:44:10Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG custodia 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG custodia 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG dogtag 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG nsContainer 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG dogtag 2018-02-15T06:44:10Z DEBUG [] 2018-02-15T06:44:10Z DEBUG Updated 0 2018-02-15T06:44:10Z DEBUG Done 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/73-winsync.update' 2018-02-15T06:44:10Z DEBUG New entry: uid=passsync,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG addifexist: 'inetUser' to objectClass, current value [] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG Parsing update file '/usr/share/ipa/updates/80-schema_compat.update' 2018-02-15T06:44:10Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginid: 2018-02-15T06:44:10Z DEBUG schema-compat-plugin 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Schema Compatibility 2018-02-15T06:44:10Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG objectclass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugindescription: 2018-02-15T06:44:10Z DEBUG Schema Compatibility Plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginenabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginpath: 2018-02-15T06:44:10Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2018-02-15T06:44:10Z DEBUG nsslapd-pluginversion: 2018-02-15T06:44:10Z DEBUG 0.8 2018-02-15T06:44:10Z DEBUG nsslapd-pluginvendor: 2018-02-15T06:44:10Z DEBUG redhat.com 2018-02-15T06:44:10Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG nsslapd-plugintype: 2018-02-15T06:44:10Z DEBUG object 2018-02-15T06:44:10Z DEBUG nsslapd-plugininitfunc: 2018-02-15T06:44:10Z DEBUG schema_compat_plugin_init 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG nsslapd-pluginid: 2018-02-15T06:44:10Z DEBUG schema-compat-plugin 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG Schema Compatibility 2018-02-15T06:44:10Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG objectclass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG nsSlapdPlugin 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG nsslapd-plugindescription: 2018-02-15T06:44:10Z DEBUG Schema Compatibility Plugin 2018-02-15T06:44:10Z DEBUG nsslapd-pluginenabled: 2018-02-15T06:44:10Z DEBUG on 2018-02-15T06:44:10Z DEBUG nsslapd-pluginpath: 2018-02-15T06:44:10Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2018-02-15T06:44:10Z DEBUG nsslapd-pluginversion: 2018-02-15T06:44:10Z DEBUG 0.8 2018-02-15T06:44:10Z DEBUG nsslapd-pluginvendor: 2018-02-15T06:44:10Z DEBUG redhat.com 2018-02-15T06:44:10Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:10Z DEBUG 40 2018-02-15T06:44:10Z DEBUG nsslapd-plugintype: 2018-02-15T06:44:10Z DEBUG object 2018-02-15T06:44:10Z DEBUG nsslapd-plugininitfunc: 2018-02-15T06:44:10Z DEBUG schema_compat_plugin_init 2018-02-15T06:44:10Z DEBUG New entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:10Z DEBUG objectclass=posixAccount 2018-02-15T06:44:10Z DEBUG gecos=%{cn} 2018-02-15T06:44:10Z DEBUG cn=%{cn} 2018-02-15T06:44:10Z DEBUG uidNumber=%{uidNumber} 2018-02-15T06:44:10Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:10Z DEBUG loginShell=%{loginShell} 2018-02-15T06:44:10Z DEBUG homeDirectory=%{homeDirectory} 2018-02-15T06:44:10Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:10Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:10Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:10Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG users 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:10Z DEBUG objectclass=posixAccount 2018-02-15T06:44:10Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:10Z DEBUG cn=users 2018-02-15T06:44:10Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:10Z DEBUG uid=%{uid} 2018-02-15T06:44:10Z DEBUG schema-compat-search-base: 2018-02-15T06:44:10Z DEBUG cn=users, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG schema-compat-container-group: 2018-02-15T06:44:10Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:10Z DEBUG objectclass=posixAccount 2018-02-15T06:44:10Z DEBUG gecos=%{cn} 2018-02-15T06:44:10Z DEBUG cn=%{cn} 2018-02-15T06:44:10Z DEBUG uidNumber=%{uidNumber} 2018-02-15T06:44:10Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:10Z DEBUG loginShell=%{loginShell} 2018-02-15T06:44:10Z DEBUG homeDirectory=%{homeDirectory} 2018-02-15T06:44:10Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:10Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:10Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:10Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG users 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:10Z DEBUG objectclass=posixAccount 2018-02-15T06:44:10Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:10Z DEBUG cn=users 2018-02-15T06:44:10Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:10Z DEBUG uid=%{uid} 2018-02-15T06:44:10Z DEBUG schema-compat-search-base: 2018-02-15T06:44:10Z DEBUG cn=users, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG schema-compat-container-group: 2018-02-15T06:44:10Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG New entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:10Z DEBUG objectclass=posixGroup 2018-02-15T06:44:10Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:10Z DEBUG memberUid=%{memberUid} 2018-02-15T06:44:10Z DEBUG memberUid=%deref_r("member","uid") 2018-02-15T06:44:10Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:10Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:10Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:10Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG groups 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:10Z DEBUG objectclass=posixGroup 2018-02-15T06:44:10Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:10Z DEBUG cn=groups 2018-02-15T06:44:10Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:10Z DEBUG cn=%{cn} 2018-02-15T06:44:10Z DEBUG schema-compat-search-base: 2018-02-15T06:44:10Z DEBUG cn=groups, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG schema-compat-container-group: 2018-02-15T06:44:10Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:10Z DEBUG objectclass=posixGroup 2018-02-15T06:44:10Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:10Z DEBUG memberUid=%{memberUid} 2018-02-15T06:44:10Z DEBUG memberUid=%deref_r("member","uid") 2018-02-15T06:44:10Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:10Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:10Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:10Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG groups 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:10Z DEBUG objectclass=posixGroup 2018-02-15T06:44:10Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:10Z DEBUG cn=groups 2018-02-15T06:44:10Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:10Z DEBUG cn=%{cn} 2018-02-15T06:44:10Z DEBUG schema-compat-search-base: 2018-02-15T06:44:10Z DEBUG cn=groups, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG schema-compat-container-group: 2018-02-15T06:44:10Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG New entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG add: 'top' to objectClass, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top'] 2018-02-15T06:44:10Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'extensibleObject'] 2018-02-15T06:44:10Z DEBUG add: 'ng' to cn, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'ng'] 2018-02-15T06:44:10Z DEBUG add: 'cn=compat, dc=pytest,dc=test' to schema-compat-container-group, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=compat, dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=ng'] 2018-02-15T06:44:10Z DEBUG add: 'yes' to schema-compat-check-access, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'yes'] 2018-02-15T06:44:10Z DEBUG add: 'cn=ng, cn=alt, dc=pytest,dc=test' to schema-compat-search-base, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=ng, cn=alt, dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(objectclass=ipaNisNetgroup)'] 2018-02-15T06:44:10Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=%{cn}'] 2018-02-15T06:44:10Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'objectclass=nisNetgroup'] 2018-02-15T06:44:10Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value [u'objectclass=nisNetgroup'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")'] 2018-02-15T06:44:10Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'] 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Final value after applying updates 2018-02-15T06:44:10Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:10Z DEBUG objectclass=nisNetgroup 2018-02-15T06:44:10Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2018-02-15T06:44:10Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2018-02-15T06:44:10Z DEBUG schema-compat-check-access: 2018-02-15T06:44:10Z DEBUG yes 2018-02-15T06:44:10Z DEBUG cn: 2018-02-15T06:44:10Z DEBUG ng 2018-02-15T06:44:10Z DEBUG objectClass: 2018-02-15T06:44:10Z DEBUG top 2018-02-15T06:44:10Z DEBUG extensibleObject 2018-02-15T06:44:10Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:10Z DEBUG (objectclass=ipaNisNetgroup) 2018-02-15T06:44:10Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:10Z DEBUG cn=ng 2018-02-15T06:44:10Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:10Z DEBUG cn=%{cn} 2018-02-15T06:44:10Z DEBUG schema-compat-search-base: 2018-02-15T06:44:10Z DEBUG cn=ng, cn=alt, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG schema-compat-container-group: 2018-02-15T06:44:10Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:10Z DEBUG New entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG --------------------------------------------- 2018-02-15T06:44:10Z DEBUG Initial value 2018-02-15T06:44:10Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:10Z DEBUG add: 'top' to objectClass, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top'] 2018-02-15T06:44:10Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'top', u'extensibleObject'] 2018-02-15T06:44:10Z DEBUG add: 'sudoers' to cn, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'sudoers'] 2018-02-15T06:44:10Z DEBUG add: 'ou=SUDOers, dc=pytest,dc=test' to schema-compat-container-group, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'ou=SUDOers, dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: 'cn=sudorules, cn=sudo, dc=pytest,dc=test' to schema-compat-search-base, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'cn=sudorules, cn=sudo, dc=pytest,dc=test'] 2018-02-15T06:44:10Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] 2018-02-15T06:44:10Z DEBUG add: '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")' to schema-compat-entry-rdn, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2018-02-15T06:44:10Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value [] 2018-02-15T06:44:10Z DEBUG add: updated value [u'objectclass=sudoRole'] 2018-02-15T06:44:10Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2018-02-15T06:44:10Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2018-02-15T06:44:10Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2018-02-15T06:44:10Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2018-02-15T06:44:10Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2018-02-15T06:44:10Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2018-02-15T06:44:10Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=sudoRole 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoOption=%{ipaSudoOpt} 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG sudoers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=sudorules, cn=sudo, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG ou=SUDOers, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG New entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=device 2018-02-15T06:44:11Z DEBUG objectclass=ieee802Device 2018-02-15T06:44:11Z DEBUG cn=%{fqdn} 2018-02-15T06:44:11Z DEBUG macAddress=%{macAddress} 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG computers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=computers 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%first("%{fqdn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=computers, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=device 2018-02-15T06:44:11Z DEBUG objectclass=ieee802Device 2018-02-15T06:44:11Z DEBUG cn=%{fqdn} 2018-02-15T06:44:11Z DEBUG macAddress=%{macAddress} 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG computers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=computers 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%first("%{fqdn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=computers, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG directoryServerFeature 2018-02-15T06:44:11Z DEBUG aci: 2018-02-15T06:44:11Z DEBUG (targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";) 2018-02-15T06:44:11Z DEBUG oid: 2018-02-15T06:44:11Z DEBUG 2.16.840.1.113730.3.4.9 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG VLV Request Control 2018-02-15T06:44:11Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value [u'(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'] 2018-02-15T06:44:11Z DEBUG only: updated value [u'(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG directoryServerFeature 2018-02-15T06:44:11Z DEBUG aci: 2018-02-15T06:44:11Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) 2018-02-15T06:44:11Z DEBUG oid: 2018-02-15T06:44:11Z DEBUG 2.16.840.1.113730.3.4.9 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG VLV Request Control 2018-02-15T06:44:11Z DEBUG [(0, u'aci', [u'(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )']), (1, u'aci', [u'(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'])] 2018-02-15T06:44:11Z DEBUG Updated 1 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=sudoRole 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoOption=%{ipaSudoOpt} 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG sudoers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=sudorules, cn=sudo, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG ou=SUDOers, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG only: set schema-compat-entry-rdn to '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")', current value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2018-02-15T06:44:11Z DEBUG only: updated value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' not in schema-compat-entry-attribute 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' not in schema-compat-entry-attribute 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2018-02-15T06:44:11Z DEBUG remove: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' not in schema-compat-entry-attribute 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' not in schema-compat-entry-attribute 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2018-02-15T06:44:11Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' not in schema-compat-entry-attribute 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=sudoRole 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoOption=%{ipaSudoOpt} 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG sudoers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=sudorules, cn=sudo, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG ou=SUDOers, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [] 2018-02-15T06:44:11Z DEBUG Updated 0 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=sudoRole 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoOption=%{ipaSudoOpt} 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG sudoers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=sudorules, cn=sudo, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG ou=SUDOers, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2018-02-15T06:44:11Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG add: 'dc=pytest,dc=test' to schema-compat-restrict-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2018-02-15T06:44:11Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=sudoRole 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoOption=%{ipaSudoOpt} 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG sudoers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=sudorules, cn=sudo, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG ou=SUDOers, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [(2, u'schema-compat-restrict-subtree', [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config']), (2, u'schema-compat-ignore-subtree', [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test']), (0, u'schema-compat-entry-attribute', [u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'])] 2018-02-15T06:44:11Z DEBUG Updated 1 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=nisNetgroup 2018-02-15T06:44:11Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2018-02-15T06:44:11Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2018-02-15T06:44:11Z DEBUG schema-compat-check-access: 2018-02-15T06:44:11Z DEBUG yes 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG ng 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (objectclass=ipaNisNetgroup) 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=ng 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=ng, cn=alt, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG replace: updated value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})'] 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG add: 'dc=pytest,dc=test' to schema-compat-restrict-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2018-02-15T06:44:11Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=nisNetgroup 2018-02-15T06:44:11Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2018-02-15T06:44:11Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2018-02-15T06:44:11Z DEBUG schema-compat-check-access: 2018-02-15T06:44:11Z DEBUG yes 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG ng 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (objectclass=ipaNisNetgroup) 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=ng 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=ng, cn=alt, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [(2, u'schema-compat-restrict-subtree', [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config']), (2, u'schema-compat-ignore-subtree', [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test']), (0, u'schema-compat-entry-attribute', [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})']), (1, u'schema-compat-entry-attribute', [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'])] 2018-02-15T06:44:11Z DEBUG Updated 1 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=device 2018-02-15T06:44:11Z DEBUG objectclass=ieee802Device 2018-02-15T06:44:11Z DEBUG cn=%{fqdn} 2018-02-15T06:44:11Z DEBUG macAddress=%{macAddress} 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG computers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=computers 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%first("%{fqdn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=computers, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG add: 'dc=pytest,dc=test' to schema-compat-restrict-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2018-02-15T06:44:11Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=device 2018-02-15T06:44:11Z DEBUG objectclass=ieee802Device 2018-02-15T06:44:11Z DEBUG cn=%{fqdn} 2018-02-15T06:44:11Z DEBUG macAddress=%{macAddress} 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG computers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=computers 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%first("%{fqdn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=computers, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [(2, u'schema-compat-restrict-subtree', [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config']), (2, u'schema-compat-ignore-subtree', [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'])] 2018-02-15T06:44:11Z DEBUG Updated 1 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=sudoRole 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoOption=%{ipaSudoOpt} 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG sudoers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=sudorules, cn=sudo, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG ou=SUDOers, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG add: 'sudoOrder=%{sudoOrder}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=sudoRole 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2018-02-15T06:44:11Z DEBUG sudoOption=%{ipaSudoOpt} 2018-02-15T06:44:11Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2018-02-15T06:44:11Z DEBUG sudoOrder=%{sudoOrder} 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG sudoers 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=sudorules, cn=sudo, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG ou=SUDOers, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [(0, u'schema-compat-entry-attribute', [u'sudoOrder=%{sudoOrder}'])] 2018-02-15T06:44:11Z DEBUG Updated 1 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG gecos=%{cn} 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG uidNumber=%{uidNumber} 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG loginShell=%{loginShell} 2018-02-15T06:44:11Z DEBUG homeDirectory=%{homeDirectory} 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG users 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=users 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG uid=%{uid} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=users, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG add: 'dc=pytest,dc=test' to schema-compat-restrict-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2018-02-15T06:44:11Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG gecos=%{cn} 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG uidNumber=%{uidNumber} 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG loginShell=%{loginShell} 2018-02-15T06:44:11Z DEBUG homeDirectory=%{homeDirectory} 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG users 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=users 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG uid=%{uid} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=users, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [(2, u'schema-compat-restrict-subtree', [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config']), (2, u'schema-compat-ignore-subtree', [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'])] 2018-02-15T06:44:11Z DEBUG Updated 1 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixGroup 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG memberUid=%{memberUid} 2018-02-15T06:44:11Z DEBUG memberUid=%deref_r("member","uid") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG groups 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixGroup 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=groups 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=groups, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2018-02-15T06:44:11Z DEBUG add: 'dc=pytest,dc=test' to schema-compat-restrict-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2018-02-15T06:44:11Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixGroup 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG memberUid=%{memberUid} 2018-02-15T06:44:11Z DEBUG memberUid=%deref_r("member","uid") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG groups 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixGroup 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=groups 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=groups, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [(2, u'schema-compat-restrict-subtree', [u'dc=pytest,dc=test', u'cn=Schema Compatibility,cn=plugins,cn=config']), (2, u'schema-compat-ignore-subtree', [u'cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test', u'cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test'])] 2018-02-15T06:44:11Z DEBUG Updated 1 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:44:11Z DEBUG on 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG Schema Compatibility 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG nsSlapdPlugin 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:11Z DEBUG Schema Compatibility Plugin 2018-02-15T06:44:11Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:11Z DEBUG on 2018-02-15T06:44:11Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:11Z DEBUG schema-compat-plugin 2018-02-15T06:44:11Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:11Z DEBUG 0.8 2018-02-15T06:44:11Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:11Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2018-02-15T06:44:11Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:11Z DEBUG redhat.com 2018-02-15T06:44:11Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:11Z DEBUG 40 2018-02-15T06:44:11Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:11Z DEBUG object 2018-02-15T06:44:11Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:11Z DEBUG schema_compat_plugin_init 2018-02-15T06:44:11Z DEBUG add: '40' to nsslapd-pluginprecedence, current value [u'40'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'40'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG nsslapd-pluginbetxn: 2018-02-15T06:44:11Z DEBUG on 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG Schema Compatibility 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG nsSlapdPlugin 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG nsslapd-pluginDescription: 2018-02-15T06:44:11Z DEBUG Schema Compatibility Plugin 2018-02-15T06:44:11Z DEBUG nsslapd-pluginEnabled: 2018-02-15T06:44:11Z DEBUG on 2018-02-15T06:44:11Z DEBUG nsslapd-pluginId: 2018-02-15T06:44:11Z DEBUG schema-compat-plugin 2018-02-15T06:44:11Z DEBUG nsslapd-pluginVersion: 2018-02-15T06:44:11Z DEBUG 0.8 2018-02-15T06:44:11Z DEBUG nsslapd-pluginPath: 2018-02-15T06:44:11Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2018-02-15T06:44:11Z DEBUG nsslapd-pluginVendor: 2018-02-15T06:44:11Z DEBUG redhat.com 2018-02-15T06:44:11Z DEBUG nsslapd-pluginprecedence: 2018-02-15T06:44:11Z DEBUG 40 2018-02-15T06:44:11Z DEBUG nsslapd-pluginType: 2018-02-15T06:44:11Z DEBUG object 2018-02-15T06:44:11Z DEBUG nsslapd-pluginInitfunc: 2018-02-15T06:44:11Z DEBUG schema_compat_plugin_init 2018-02-15T06:44:11Z DEBUG [] 2018-02-15T06:44:11Z DEBUG Updated 0 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG gecos=%{cn} 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG uidNumber=%{uidNumber} 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG loginShell=%{loginShell} 2018-02-15T06:44:11Z DEBUG homeDirectory=%{homeDirectory} 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG users 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=users 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG uid=%{uid} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=users, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2018-02-15T06:44:11Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")'] 2018-02-15T06:44:11Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2018-02-15T06:44:11Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG gecos=%{cn} 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG uidNumber=%{uidNumber} 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG loginShell=%{loginShell} 2018-02-15T06:44:11Z DEBUG homeDirectory=%{homeDirectory} 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG users 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=users 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG uid=%{uid} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=users, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [] 2018-02-15T06:44:11Z DEBUG Updated 0 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixGroup 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG memberUid=%{memberUid} 2018-02-15T06:44:11Z DEBUG memberUid=%deref_r("member","uid") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG groups 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=groups 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixGroup 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=groups, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2018-02-15T06:44:11Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")'] 2018-02-15T06:44:11Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2018-02-15T06:44:11Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixGroup 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG memberUid=%{memberUid} 2018-02-15T06:44:11Z DEBUG memberUid=%deref_r("member","uid") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG groups 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=groups 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixGroup 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=groups, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [] 2018-02-15T06:44:11Z DEBUG Updated 0 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Initial value 2018-02-15T06:44:11Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG gecos=%{cn} 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG uidNumber=%{uidNumber} 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG loginShell=%{loginShell} 2018-02-15T06:44:11Z DEBUG homeDirectory=%{homeDirectory} 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG users 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=users 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG uid=%{uid} 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=users, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG add: 'uid=%{uid}' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2018-02-15T06:44:11Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}'] 2018-02-15T06:44:11Z DEBUG replace: updated value [u'uid=%first("%{uid}")'] 2018-02-15T06:44:11Z DEBUG --------------------------------------------- 2018-02-15T06:44:11Z DEBUG Final value after applying updates 2018-02-15T06:44:11Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-entry-attribute: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG gecos=%{cn} 2018-02-15T06:44:11Z DEBUG cn=%{cn} 2018-02-15T06:44:11Z DEBUG uidNumber=%{uidNumber} 2018-02-15T06:44:11Z DEBUG gidNumber=%{gidNumber} 2018-02-15T06:44:11Z DEBUG loginShell=%{loginShell} 2018-02-15T06:44:11Z DEBUG homeDirectory=%{homeDirectory} 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:pytest.test:%{ipauniqueid}","") 2018-02-15T06:44:11Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2018-02-15T06:44:11Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2018-02-15T06:44:11Z DEBUG uid=%{uid} 2018-02-15T06:44:11Z DEBUG cn: 2018-02-15T06:44:11Z DEBUG users 2018-02-15T06:44:11Z DEBUG objectClass: 2018-02-15T06:44:11Z DEBUG top 2018-02-15T06:44:11Z DEBUG extensibleObject 2018-02-15T06:44:11Z DEBUG schema-compat-container-rdn: 2018-02-15T06:44:11Z DEBUG cn=users 2018-02-15T06:44:11Z DEBUG schema-compat-restrict-subtree: 2018-02-15T06:44:11Z DEBUG dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2018-02-15T06:44:11Z DEBUG schema-compat-search-filter: 2018-02-15T06:44:11Z DEBUG objectclass=posixAccount 2018-02-15T06:44:11Z DEBUG schema-compat-ignore-subtree: 2018-02-15T06:44:11Z DEBUG cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-entry-rdn: 2018-02-15T06:44:11Z DEBUG uid=%first("%{uid}") 2018-02-15T06:44:11Z DEBUG schema-compat-search-base: 2018-02-15T06:44:11Z DEBUG cn=users, cn=accounts, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG schema-compat-container-group: 2018-02-15T06:44:11Z DEBUG cn=compat, dc=pytest,dc=test 2018-02-15T06:44:11Z DEBUG [(0, u'schema-compat-entry-rdn', [u'uid=%first("%{uid}")']), (1, u'schema-compat-entry-rdn', [u'uid=%{uid}']), (0, u'schema-compat-entry-attribute', [u'uid=%{uid}'])] 2018-02-15T06:44:11Z DEBUG Updated 1 2018-02-15T06:44:11Z DEBUG Done 2018-02-15T06:44:11Z DEBUG Parsing update file '/usr/share/ipa/updates/90-post_upgrade_plugins.update' 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_ca_topology 2018-02-15T06:44:11Z DEBUG raw: update_ca_topology 2018-02-15T06:44:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:11Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:44:11Z DEBUG CA is not configured on this host 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_ipaconfigstring_dnsversion_to_ipadnsversion 2018-02-15T06:44:11Z DEBUG raw: update_ipaconfigstring_dnsversion_to_ipadnsversion 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_dnszones 2018-02-15T06:44:11Z DEBUG raw: update_dnszones 2018-02-15T06:44:11Z DEBUG raw: dnszone_find(None, all=True, version=u'2.228') 2018-02-15T06:44:11Z DEBUG dnszone_find(None, forward_only=False, all=True, raw=False, version=u'2.228', pkey_only=False) 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_dns_limits 2018-02-15T06:44:11Z DEBUG raw: update_dns_limits 2018-02-15T06:44:11Z DEBUG DNS: service krbprincipalname=DNS/replica3.pytest.test@PYTEST.TEST,cn=services,cn=accounts,dc=pytest,dc=test not found, no need to update limits 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_sigden_extdom_broken_config 2018-02-15T06:44:11Z DEBUG raw: update_sigden_extdom_broken_config 2018-02-15T06:44:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:11Z DEBUG configured basedn for cn=IPA SIDGEN,cn=plugins,cn=config is okay 2018-02-15T06:44:11Z DEBUG configured basedn for cn=ipa_extdom_extop,cn=plugins,cn=config is okay 2018-02-15T06:44:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:11Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_sids 2018-02-15T06:44:11Z DEBUG raw: update_sids 2018-02-15T06:44:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:11Z DEBUG SIDs do not need to be generated 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_default_range 2018-02-15T06:44:11Z DEBUG raw: update_default_range 2018-02-15T06:44:11Z DEBUG default_range: ipaDomainIDRange entry found, skip plugin 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_default_trust_view 2018-02-15T06:44:11Z DEBUG raw: update_default_trust_view 2018-02-15T06:44:11Z DEBUG raw: adtrust_is_enabled(version=u'2.228') 2018-02-15T06:44:11Z DEBUG adtrust_is_enabled(version=u'2.228') 2018-02-15T06:44:11Z DEBUG AD Trusts are not enabled on this server 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_tdo_gidnumber 2018-02-15T06:44:11Z DEBUG raw: update_tdo_gidnumber 2018-02-15T06:44:11Z DEBUG raw: adtrust_is_enabled(version=u'2.228') 2018-02-15T06:44:11Z DEBUG adtrust_is_enabled(version=u'2.228') 2018-02-15T06:44:11Z DEBUG AD Trusts are not enabled on this server 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_ca_renewal_master 2018-02-15T06:44:11Z DEBUG raw: update_ca_renewal_master 2018-02-15T06:44:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:11Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:44:11Z DEBUG CA is not configured on this host 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_idrange_type 2018-02-15T06:44:11Z DEBUG raw: update_idrange_type 2018-02-15T06:44:11Z DEBUG update_idrange_type: search for ID ranges with no type set 2018-02-15T06:44:11Z DEBUG update_idrange_type: no ID range without type set found 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_pacs 2018-02-15T06:44:11Z DEBUG raw: update_pacs 2018-02-15T06:44:11Z DEBUG PAC for nfs is already set, not adding nfs:NONE. 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_service_principalalias 2018-02-15T06:44:11Z DEBUG raw: update_service_principalalias 2018-02-15T06:44:11Z DEBUG update_service_principalalias: search for affected services 2018-02-15T06:44:11Z DEBUG update_service_principalalias: found 2 services to update, truncated: False 2018-02-15T06:44:11Z DEBUG update_service_principalalias: all affected services updated 2018-02-15T06:44:11Z DEBUG Executing upgrade plugin: update_fix_duplicate_cacrt_in_ldap 2018-02-15T06:44:11Z DEBUG raw: update_fix_duplicate_cacrt_in_ldap 2018-02-15T06:44:11Z DEBUG raw: ca_is_enabled(version=u'2.228') 2018-02-15T06:44:11Z DEBUG ca_is_enabled(version=u'2.228') 2018-02-15T06:44:11Z DEBUG Destroyed connection context.ldap2_140099962487952 2018-02-15T06:44:11Z DEBUG Restarting directory server to apply updates 2018-02-15T06:44:11Z DEBUG Destroyed connection context.ldap2_140100023575440 2018-02-15T06:44:11Z DEBUG Starting external process 2018-02-15T06:44:11Z DEBUG args=/bin/systemctl restart dirsrv@PYTEST-TEST.service 2018-02-15T06:44:18Z DEBUG Process finished, return code=0 2018-02-15T06:44:18Z DEBUG stdout= 2018-02-15T06:44:18Z DEBUG stderr= 2018-02-15T06:44:18Z DEBUG Created connection context.ldap2_140100023575440 2018-02-15T06:44:18Z DEBUG Created connection context.ldap2_140099962487952 2018-02-15T06:44:18Z DEBUG Executing upgrade plugin: update_upload_cacrt 2018-02-15T06:44:18Z DEBUG raw: update_upload_cacrt 2018-02-15T06:44:18Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:44:18Z DEBUG raw: ca_is_enabled(version=u'2.228') 2018-02-15T06:44:18Z DEBUG ca_is_enabled(version=u'2.228') 2018-02-15T06:44:18Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket from SchemaCache 2018-02-15T06:44:18Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket conn= 2018-02-15T06:44:19Z DEBUG Starting external process 2018-02-15T06:44:19Z DEBUG args=/usr/bin/certutil -d /etc/httpd/alias -L -f /etc/httpd/alias/pwdfile.txt 2018-02-15T06:44:19Z DEBUG Process finished, return code=0 2018-02-15T06:44:19Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI Server-Cert u,u,u PYTEST.TEST IPA CA CT,C,C 2018-02-15T06:44:19Z DEBUG stderr= 2018-02-15T06:44:19Z DEBUG Starting external process 2018-02-15T06:44:19Z DEBUG args=/usr/bin/certutil -d /etc/httpd/alias -L -n PYTEST.TEST IPA CA -a -f /etc/httpd/alias/pwdfile.txt 2018-02-15T06:44:19Z DEBUG Process finished, return code=0 2018-02-15T06:44:19Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIDizCCAnOgAwIBAgIBATANBgkqhkiG9w0BAQsFADA2MRQwEgYDVQQKDAtQWVRF U1QuVEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE4MDIx NDA1NDM1NloXDTM4MDIxNDA1NDM1NlowNjEUMBIGA1UECgwLUFlURVNULlRFU1Qx HjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEB BQADggEPADCCAQoCggEBALyHv9Rolz8gwuqBDIr9bUFbCteHNqZ+i2P6hVGE1wX4 dtG2kZrevk2T8+JO+8+4H3swPvXUUHypCNClIk8qJy95xM+4/PaQGd/V7NPftxVf 4DdA2VwnRtOayuJj73aOFqyqHwvdOn/bcaM6+/ANL0iyFz9UJDVit+WYpuZzgt7V loRILeNwXMXHL5PJzXIrYVSCG2F/8GBPZ21Ud+2cWSOiP+t/rjRVgglZZJ9RaNYo Rb475/KpaqU9o1pCz/+gTTQ+VT2SpJ2CkmMtEeTEEsYUolOZsu83FiQV7+4yaS4t T1CwyYTM6mUVzGSRzx/7j7a16G8SnUEy41zvFldN1F8CAwEAAaOBozCBoDAfBgNV HSMEGDAWgBSgdFNDa/PCc155d6M2D1g8mMSJSjAPBgNVHRMBAf8EBTADAQH/MA4G A1UdDwEB/wQEAwIBxjAdBgNVHQ4EFgQUoHRTQ2vzwnNeeXejNg9YPJjEiUowPQYI KwYBBQUHAQEEMTAvMC0GCCsGAQUFBzABhiFodHRwOi8vaXBhLWNhLnB5dGVzdC50 ZXN0L2NhL29jc3AwDQYJKoZIhvcNAQELBQADggEBAI6tiQWB5zPCQAlGwjUqeTbt +zOzPSvfwHQ9Joos1GzQKLq876RUVZTr4bqrZ9sKkkRGmkxnn+GU8uwXwsmjKqTo eer6Z7KMK4liPtBI9tM6G3w66b26PblUI3OC3sOU7eXpNfJrmgbVc5RghIxHnCO1 8uSjBVFhY1IMfUiANsWD8paRDh85wdKdJETZxsky/C2TRac4w6j9XsKuGbW8w+4Y LTkNEQNHncvaEDs/F39OiGaePxYVUzaZHZne3STWlb/i+fp+dfO8JCNyDwwnVCPh ma/UGrWNQ+YmrUbFPEX53y6bVV29vYi+yc/zB/QMTF+n7SskZde7afYhtTCmYVk= -----END CERTIFICATE----- 2018-02-15T06:44:19Z DEBUG stderr= 2018-02-15T06:44:19Z DEBUG Executing upgrade plugin: update_ra_cert_store 2018-02-15T06:44:19Z DEBUG raw: update_ra_cert_store 2018-02-15T06:44:19Z DEBUG raw: ca_is_enabled(version=u'2.228') 2018-02-15T06:44:19Z DEBUG ca_is_enabled(version=u'2.228') 2018-02-15T06:44:19Z DEBUG Starting external process 2018-02-15T06:44:19Z DEBUG args=/usr/bin/certutil -d /etc/httpd/alias -L -n ipaCert -a -f /etc/httpd/alias/pwdfile.txt 2018-02-15T06:44:19Z DEBUG Process finished, return code=255 2018-02-15T06:44:19Z DEBUG stdout= 2018-02-15T06:44:19Z DEBUG stderr=certutil: Could not find cert: ipaCert : PR_FILE_NOT_FOUND_ERROR: File not found 2018-02-15T06:44:19Z DEBUG Executing upgrade plugin: update_master_to_dnsforwardzones 2018-02-15T06:44:19Z DEBUG raw: update_master_to_dnsforwardzones 2018-02-15T06:44:19Z DEBUG raw: dnsconfig_show(all=True, version=u'2.228') 2018-02-15T06:44:19Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version=u'2.228') 2018-02-15T06:44:19Z DEBUG Executing upgrade plugin: update_dnsforward_emptyzones 2018-02-15T06:44:19Z DEBUG raw: update_dnsforward_emptyzones 2018-02-15T06:44:19Z DEBUG raw: dnsconfig_show(all=True, version=u'2.228') 2018-02-15T06:44:19Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version=u'2.228') 2018-02-15T06:44:19Z DEBUG Executing upgrade plugin: update_managed_post 2018-02-15T06:44:19Z DEBUG raw: update_managed_post 2018-02-15T06:44:19Z DEBUG Executing upgrade plugin: update_managed_permissions 2018-02-15T06:44:19Z DEBUG raw: update_managed_permissions 2018-02-15T06:44:19Z DEBUG Anonymous ACI not found 2018-02-15T06:44:19Z DEBUG Updating managed permissions for automember 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Automember Definitions 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Automember Definitions 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Automember Rules 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Automember Rules 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Automember Tasks 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Automember Tasks 2018-02-15T06:44:19Z DEBUG Updating managed permissions for automountkey 2018-02-15T06:44:19Z DEBUG Legacy permission Add Automount keys not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Automount Keys 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Automount Keys 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Automount keys not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Automount Keys 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Automount Keys 2018-02-15T06:44:19Z DEBUG Legacy permission Remove Automount keys not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Automount Keys 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Automount Keys 2018-02-15T06:44:19Z DEBUG Updating managed permissions for automountlocation 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Automount Locations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Automount Locations 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Automount Configuration 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Automount Configuration 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Automount Locations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Automount Locations 2018-02-15T06:44:19Z DEBUG Updating managed permissions for automountmap 2018-02-15T06:44:19Z DEBUG Legacy permission Add Automount maps not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Automount Maps 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Automount Maps 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Automount maps not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Automount Maps 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Automount Maps 2018-02-15T06:44:19Z DEBUG Legacy permission Remove Automount maps not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Automount Maps 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Automount Maps 2018-02-15T06:44:19Z DEBUG Updating managed permissions for ca 2018-02-15T06:44:19Z DEBUG Legacy permission Add CA not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add CA 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add CA 2018-02-15T06:44:19Z DEBUG Legacy permission Delete CA not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Delete CA 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Delete CA 2018-02-15T06:44:19Z DEBUG Legacy permission Modify CA not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify CA 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify CA 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read CAs 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read CAs 2018-02-15T06:44:19Z DEBUG Updating managed permissions for caacl 2018-02-15T06:44:19Z DEBUG Legacy permission Add CA ACL not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add CA ACL 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add CA ACL 2018-02-15T06:44:19Z DEBUG Legacy permission Delete CA ACL not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Delete CA ACL 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Delete CA ACL 2018-02-15T06:44:19Z DEBUG Legacy permission Manage CA ACL membership not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage CA ACL Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage CA ACL Membership 2018-02-15T06:44:19Z DEBUG Legacy permission Modify CA ACL not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify CA ACL 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify CA ACL 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read CA ACLs 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read CA ACLs 2018-02-15T06:44:19Z DEBUG Updating managed permissions for certmapconfig 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Certmap Configuration 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Certmap Configuration 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Certmap Configuration 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Certmap Configuration 2018-02-15T06:44:19Z DEBUG Updating managed permissions for certmaprule 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Certmap Rules 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Certmap Rules 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Delete Certmap Rules 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Delete Certmap Rules 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Certmap Rules 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Certmap Rules 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Certmap Rules 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Certmap Rules 2018-02-15T06:44:19Z DEBUG Updating managed permissions for certprofile 2018-02-15T06:44:19Z DEBUG Legacy permission Delete Certificate Profile not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Delete Certificate Profile 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Delete Certificate Profile 2018-02-15T06:44:19Z DEBUG Legacy permission Import Certificate Profile not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Import Certificate Profile 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Import Certificate Profile 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Certificate Profile not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Certificate Profile 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Certificate Profile 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Certificate Profiles 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Certificate Profiles 2018-02-15T06:44:19Z DEBUG Updating managed permissions for config 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Global Configuration 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Global Configuration 2018-02-15T06:44:19Z DEBUG Updating managed permissions for cosentry 2018-02-15T06:44:19Z DEBUG Legacy permission Add Group Password Policy costemplate not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Group Password Policy costemplate 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Group Password Policy costemplate 2018-02-15T06:44:19Z DEBUG Legacy permission Delete Group Password Policy costemplate not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Delete Group Password Policy costemplate 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Delete Group Password Policy costemplate 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Group Password Policy costemplate not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Group Password Policy costemplate 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Group Password Policy costemplate 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Group Password Policy costemplate 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Group Password Policy costemplate 2018-02-15T06:44:19Z DEBUG Updating managed permissions for dnsconfig 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read DNS Configuration 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read DNS Configuration 2018-02-15T06:44:19Z DEBUG Legacy permission Write DNS Configuration not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Write DNS Configuration 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Write DNS Configuration 2018-02-15T06:44:19Z DEBUG Updating managed permissions for dnsserver 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify DNS Servers Configuration 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify DNS Servers Configuration 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read DNS Servers Configuration 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read DNS Servers Configuration 2018-02-15T06:44:19Z DEBUG Updating managed permissions for dnszone 2018-02-15T06:44:19Z DEBUG Legacy permission add dns entries not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add DNS Entries 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add DNS Entries 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage DNSSEC keys 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage DNSSEC keys 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage DNSSEC metadata 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage DNSSEC metadata 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read DNS Entries 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read DNS Entries 2018-02-15T06:44:19Z DEBUG Legacy permission 'Read DNS Entries' not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read DNSSEC metadata 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read DNSSEC metadata 2018-02-15T06:44:19Z DEBUG Legacy permission remove dns entries not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove DNS Entries 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove DNS Entries 2018-02-15T06:44:19Z DEBUG Legacy permission update dns entries not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Update DNS Entries 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Update DNS Entries 2018-02-15T06:44:19Z DEBUG Updating managed permissions for group 2018-02-15T06:44:19Z DEBUG Legacy permission Add Groups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Groups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Groups 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify External Group Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify External Group Membership 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Group membership not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Group Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Group Membership 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Groups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Groups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Groups 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read External Group Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read External Group Membership 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Group Compat Tree 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Group Compat Tree 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Group Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Group Membership 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Group Views Compat Tree 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Group Views Compat Tree 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Groups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Groups 2018-02-15T06:44:19Z DEBUG Legacy permission Remove Groups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Groups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Groups 2018-02-15T06:44:19Z DEBUG Updating managed permissions for hbacrule 2018-02-15T06:44:19Z DEBUG Legacy permission Add HBAC rule not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add HBAC Rule 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add HBAC Rule 2018-02-15T06:44:19Z DEBUG Legacy permission Delete HBAC rule not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Delete HBAC Rule 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Delete HBAC Rule 2018-02-15T06:44:19Z DEBUG Legacy permission Manage HBAC rule membership not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage HBAC Rule Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage HBAC Rule Membership 2018-02-15T06:44:19Z DEBUG Legacy permission Modify HBAC rule not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify HBAC Rule 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify HBAC Rule 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read HBAC Rules 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read HBAC Rules 2018-02-15T06:44:19Z DEBUG Updating managed permissions for hbacsvc 2018-02-15T06:44:19Z DEBUG Legacy permission Add HBAC services not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add HBAC Services 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add HBAC Services 2018-02-15T06:44:19Z DEBUG Legacy permission Delete HBAC services not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Delete HBAC Services 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Delete HBAC Services 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read HBAC Services 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read HBAC Services 2018-02-15T06:44:19Z DEBUG Updating managed permissions for hbacsvcgroup 2018-02-15T06:44:19Z DEBUG Legacy permission Add HBAC service groups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add HBAC Service Groups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add HBAC Service Groups 2018-02-15T06:44:19Z DEBUG Legacy permission Delete HBAC service groups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Delete HBAC Service Groups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Delete HBAC Service Groups 2018-02-15T06:44:19Z DEBUG Legacy permission Manage HBAC service group membership not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage HBAC Service Group Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage HBAC Service Group Membership 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read HBAC Service Groups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read HBAC Service Groups 2018-02-15T06:44:19Z DEBUG Updating managed permissions for host 2018-02-15T06:44:19Z DEBUG Legacy permission Add Hosts not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Hosts 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Hosts 2018-02-15T06:44:19Z DEBUG Legacy permission Add krbPrincipalName to a host not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add krbPrincipalName to a Host 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add krbPrincipalName to a Host 2018-02-15T06:44:19Z DEBUG Legacy permission Enroll a host not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Enroll a Host 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Enroll a Host 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage Host Certificates 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage Host Certificates 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage Host Enrollment Password 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage Host Enrollment Password 2018-02-15T06:44:19Z DEBUG Legacy permission Manage host keytab not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage Host Keytab 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage Host Keytab 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage Host Keytab Permissions 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage Host Keytab Permissions 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage Host Principals 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage Host Principals 2018-02-15T06:44:19Z DEBUG Legacy permission Manage Host SSH Public Keys not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage Host SSH Public Keys 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage Host SSH Public Keys 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Hosts not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Hosts 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Hosts 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Host Compat Tree 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Host Compat Tree 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Host Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Host Membership 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Hosts 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Hosts 2018-02-15T06:44:19Z DEBUG Legacy permission Remove Hosts not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Hosts 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Hosts 2018-02-15T06:44:19Z DEBUG Updating managed permissions for hostgroup 2018-02-15T06:44:19Z DEBUG Legacy permission Add Hostgroups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Hostgroups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Hostgroups 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Hostgroup membership not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Hostgroup Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Hostgroup Membership 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Hostgroups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Hostgroups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Hostgroups 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Hostgroup Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Hostgroup Membership 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Hostgroups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Hostgroups 2018-02-15T06:44:19Z DEBUG Legacy permission Remove Hostgroups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Hostgroups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Hostgroups 2018-02-15T06:44:19Z DEBUG Updating managed permissions for idoverridegroup 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Group ID Overrides 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Group ID Overrides 2018-02-15T06:44:19Z DEBUG Updating managed permissions for idoverrideuser 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read User ID Overrides 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read User ID Overrides 2018-02-15T06:44:19Z DEBUG Updating managed permissions for idrange 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read ID Ranges 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read ID Ranges 2018-02-15T06:44:19Z DEBUG Updating managed permissions for idview 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read ID Views 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read ID Views 2018-02-15T06:44:19Z DEBUG Updating managed permissions for krbtpolicy 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Default Kerberos Ticket Policy 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Default Kerberos Ticket Policy 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read User Kerberos Ticket Policy 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read User Kerberos Ticket Policy 2018-02-15T06:44:19Z DEBUG Updating managed permissions for location 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add IPA Locations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add IPA Locations 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify IPA Locations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify IPA Locations 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read IPA Locations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read IPA Locations 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove IPA Locations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove IPA Locations 2018-02-15T06:44:19Z DEBUG Updating managed permissions for netgroup 2018-02-15T06:44:19Z DEBUG Legacy permission Add netgroups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Netgroups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Netgroups 2018-02-15T06:44:19Z DEBUG Legacy permission Modify netgroup membership not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Netgroup Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Netgroup Membership 2018-02-15T06:44:19Z DEBUG Legacy permission Modify netgroups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Netgroups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Netgroups 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Netgroup Compat Tree 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Netgroup Compat Tree 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Netgroup Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Netgroup Membership 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Netgroups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Netgroups 2018-02-15T06:44:19Z DEBUG Legacy permission Remove netgroups not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Netgroups 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Netgroups 2018-02-15T06:44:19Z DEBUG Updating managed permissions for otpconfig 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read OTP Configuration 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read OTP Configuration 2018-02-15T06:44:19Z DEBUG Updating managed permissions for permission 2018-02-15T06:44:19Z DEBUG Legacy permission Modify privilege membership not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Privilege Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Privilege Membership 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read ACIs 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read ACIs 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Permissions 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Permissions 2018-02-15T06:44:19Z DEBUG Updating managed permissions for privilege 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Privileges 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Privileges 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Privileges 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Privileges 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Privileges 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Privileges 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Privileges 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Privileges 2018-02-15T06:44:19Z DEBUG Updating managed permissions for pwpolicy 2018-02-15T06:44:19Z DEBUG Legacy permission Add Group Password Policy not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Group Password Policy 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Group Password Policy 2018-02-15T06:44:19Z DEBUG Legacy permission Delete Group Password Policy not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Delete Group Password Policy 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Delete Group Password Policy 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Group Password Policy not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Group Password Policy 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Group Password Policy 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Group Password Policy 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Group Password Policy 2018-02-15T06:44:19Z DEBUG Updating managed permissions for realmdomains 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Realm Domains 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Realm Domains 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Realm Domains 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Realm Domains 2018-02-15T06:44:19Z DEBUG Updating managed permissions for role 2018-02-15T06:44:19Z DEBUG Legacy permission Add Roles not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Roles 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Roles 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Role membership not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Role Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Role Membership 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Roles not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Roles 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Roles 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Roles 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Roles 2018-02-15T06:44:19Z DEBUG Legacy permission Remove Roles not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Roles 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Roles 2018-02-15T06:44:19Z DEBUG Updating managed permissions for selinuxusermap 2018-02-15T06:44:19Z DEBUG Legacy permission Add SELinux User Maps not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add SELinux User Maps 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add SELinux User Maps 2018-02-15T06:44:19Z DEBUG Legacy permission Modify SELinux User Maps not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify SELinux User Maps 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify SELinux User Maps 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read SELinux User Maps 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read SELinux User Maps 2018-02-15T06:44:19Z DEBUG Legacy permission Remove SELinux User Maps not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove SELinux User Maps 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove SELinux User Maps 2018-02-15T06:44:19Z DEBUG Updating managed permissions for server 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Locations of IPA Servers 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Locations of IPA Servers 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Status of Services on IPA Servers 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Status of Services on IPA Servers 2018-02-15T06:44:19Z DEBUG Updating managed permissions for service 2018-02-15T06:44:19Z DEBUG Legacy permission Add Services not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Services 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Services 2018-02-15T06:44:19Z DEBUG Legacy permission Manage service keytab not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage Service Keytab 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage Service Keytab 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage Service Keytab Permissions 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage Service Keytab Permissions 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Manage Service Principals 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Manage Service Principals 2018-02-15T06:44:19Z DEBUG Legacy permission Modify Services not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Services 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Services 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Services 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Services 2018-02-15T06:44:19Z DEBUG Legacy permission Remove Services not found 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Services 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Services 2018-02-15T06:44:19Z DEBUG Updating managed permissions for servicedelegationrule 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Service Delegations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Service Delegations 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Service Delegation Membership 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Service Delegations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Service Delegations 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Service Delegations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Service Delegations 2018-02-15T06:44:19Z DEBUG Updating managed permissions for servicedelegationtarget 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Service Delegations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Service Delegations 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Service Delegation Membership 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Service Delegations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Service Delegations 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Service Delegations 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Service Delegations 2018-02-15T06:44:19Z DEBUG Updating managed permissions for stageuser 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Add Stage User 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Add Stage User 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Preserved Users 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Preserved Users 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify Stage User 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify Stage User 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Modify User RDN 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Modify User RDN 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Preserve User 2018-02-15T06:44:19Z DEBUG Updating ACI for managed permission: System: Preserve User 2018-02-15T06:44:19Z DEBUG Removing ACI u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from dc=pytest,dc=test 2018-02-15T06:44:19Z DEBUG Adding ACI u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to dc=pytest,dc=test 2018-02-15T06:44:19Z DEBUG No changes to ACI 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Preserved Users 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Preserved Users 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Stage User password 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Stage User password 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Read Stage Users 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Read Stage Users 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove Stage User 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove Stage User 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Remove preserved User 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Remove preserved User 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Reset Preserved User password 2018-02-15T06:44:19Z DEBUG No changes to permission: System: Reset Preserved User password 2018-02-15T06:44:19Z DEBUG Updating managed permission: System: Undelete User 2018-02-15T06:44:19Z DEBUG Updating ACI for managed permission: System: Undelete User 2018-02-15T06:44:19Z DEBUG Removing ACI u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)' from dc=pytest,dc=test 2018-02-15T06:44:19Z DEBUG Adding ACI u'(target_to = "ldap:///cn=users,cn=accounts,dc=pytest,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=pytest,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=pytest,dc=test";)' to dc=pytest,dc=test 2018-02-15T06:44:19Z DEBUG No changes to ACI 2018-02-15T06:44:19Z DEBUG Updating managed permissions for sudocmd 2018-02-15T06:44:20Z DEBUG Legacy permission Add Sudo command not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Add Sudo Command 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Add Sudo Command 2018-02-15T06:44:20Z DEBUG Legacy permission Delete Sudo command not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Delete Sudo Command 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Delete Sudo Command 2018-02-15T06:44:20Z DEBUG Legacy permission Modify Sudo command not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Modify Sudo Command 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Modify Sudo Command 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Sudo Commands 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Sudo Commands 2018-02-15T06:44:20Z DEBUG Updating managed permissions for sudocmdgroup 2018-02-15T06:44:20Z DEBUG Legacy permission Add Sudo command group not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Add Sudo Command Group 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Add Sudo Command Group 2018-02-15T06:44:20Z DEBUG Legacy permission Delete Sudo command group not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Delete Sudo Command Group 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Delete Sudo Command Group 2018-02-15T06:44:20Z DEBUG Legacy permission Manage Sudo command group membership not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Manage Sudo Command Group Membership 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Manage Sudo Command Group Membership 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Modify Sudo Command Group 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Modify Sudo Command Group 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Sudo Command Groups 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Sudo Command Groups 2018-02-15T06:44:20Z DEBUG Updating managed permissions for sudorule 2018-02-15T06:44:20Z DEBUG Legacy permission Add Sudo rule not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Add Sudo rule 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Add Sudo rule 2018-02-15T06:44:20Z DEBUG Legacy permission Delete Sudo rule not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Delete Sudo rule 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Delete Sudo rule 2018-02-15T06:44:20Z DEBUG Legacy permission Modify Sudo rule not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Modify Sudo rule 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Modify Sudo rule 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Sudo Rules 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Sudo Rules 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Sudoers compat tree 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Sudoers compat tree 2018-02-15T06:44:20Z DEBUG Updating managed permissions for trust 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Trust Information 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Trust Information 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read system trust accounts 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read system trust accounts 2018-02-15T06:44:20Z DEBUG Updating managed permissions for user 2018-02-15T06:44:20Z DEBUG Legacy permission Add user to default group not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Add User to default group 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Add User to default group 2018-02-15T06:44:20Z DEBUG Legacy permission Add Users not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Add Users 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Add Users 2018-02-15T06:44:20Z DEBUG Legacy permission Change a user password not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Change User password 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Change User password 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Manage User Certificate Mappings 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Manage User Certificate Mappings 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Manage User Certificates 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Manage User Certificates 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Manage User Principals 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Manage User Principals 2018-02-15T06:44:20Z DEBUG Legacy permission Manage User SSH Public Keys not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Manage User SSH Public Keys 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Manage User SSH Public Keys 2018-02-15T06:44:20Z DEBUG Legacy permission Modify Users not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Modify Users 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Modify Users 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read UPG Definition 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read UPG Definition 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read User Addressbook Attributes 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read User Addressbook Attributes 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read User Compat Tree 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read User Compat Tree 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read User IPA Attributes 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read User IPA Attributes 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read User Kerberos Attributes 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read User Kerberos Attributes 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read User Kerberos Login Attributes 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read User Kerberos Login Attributes 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read User Membership 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read User Membership 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read User NT Attributes 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read User NT Attributes 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read User Standard Attributes 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read User Standard Attributes 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read User Views Compat Tree 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read User Views Compat Tree 2018-02-15T06:44:20Z DEBUG Legacy permission Remove Users not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Remove Users 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Remove Users 2018-02-15T06:44:20Z DEBUG Legacy permission Unlock user accounts not found 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Unlock User 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Unlock User 2018-02-15T06:44:20Z DEBUG Updating managed permissions for vault 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Add Vaults 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Add Vaults 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Delete Vaults 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Delete Vaults 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Manage Vault Membership 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Manage Vault Membership 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Manage Vault Ownership 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Manage Vault Ownership 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Modify Vaults 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Modify Vaults 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Vaults 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Vaults 2018-02-15T06:44:20Z DEBUG Updating managed permissions for vaultcontainer 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Add Vault Containers 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Add Vault Containers 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Delete Vault Containers 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Delete Vault Containers 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Manage Vault Container Ownership 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Manage Vault Container Ownership 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Modify Vault Containers 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Modify Vault Containers 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Vault Containers 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Vault Containers 2018-02-15T06:44:20Z DEBUG Updating non-object managed permissions 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Add CA Certificate For Renewal 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Add CA Certificate For Renewal 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Add Certificate Store Entry 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Add Certificate Store Entry 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Compat Tree ID View targets 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Compat Tree ID View targets 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Modify CA Certificate 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Modify CA Certificate 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Modify CA Certificate For Renewal 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Modify CA Certificate For Renewal 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Modify Certificate Store Entry 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Modify Certificate Store Entry 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read AD Domains 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read AD Domains 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read CA Certificate 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read CA Certificate 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read CA Renewal Information 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read CA Renewal Information 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Certificate Store Entries 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Certificate Store Entries 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read DNA Configuration 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read DNA Configuration 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read DUA Profile 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read DUA Profile 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Domain Level 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Domain Level 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read IPA Masters 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read IPA Masters 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Read Replication Information 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Read Replication Information 2018-02-15T06:44:20Z DEBUG Updating managed permission: System: Remove Certificate Store Entry 2018-02-15T06:44:20Z DEBUG No changes to permission: System: Remove Certificate Store Entry 2018-02-15T06:44:20Z DEBUG Deleting obsolete permission System: Read Creator and Modifier Operational Attributes 2018-02-15T06:44:20Z DEBUG raw: permission_del((u'System: Read Creator and Modifier Operational Attributes',), force=True, version=u'2.101') 2018-02-15T06:44:20Z DEBUG permission_del((u'System: Read Creator and Modifier Operational Attributes',), continue=False, force=True, version=u'2.101') 2018-02-15T06:44:20Z DEBUG Obsolete permission not found 2018-02-15T06:44:20Z DEBUG Deleting obsolete permission System: Read Timestamp and USN Operational Attributes 2018-02-15T06:44:20Z DEBUG raw: permission_del((u'System: Read Timestamp and USN Operational Attributes',), force=True, version=u'2.101') 2018-02-15T06:44:20Z DEBUG permission_del((u'System: Read Timestamp and USN Operational Attributes',), continue=False, force=True, version=u'2.101') 2018-02-15T06:44:20Z DEBUG Obsolete permission not found 2018-02-15T06:44:20Z DEBUG Executing upgrade plugin: update_read_replication_agreements_permission 2018-02-15T06:44:20Z DEBUG raw: update_read_replication_agreements_permission 2018-02-15T06:44:20Z DEBUG Old permission not found 2018-02-15T06:44:20Z DEBUG Executing upgrade plugin: update_idrange_baserid 2018-02-15T06:44:20Z DEBUG raw: update_idrange_baserid 2018-02-15T06:44:20Z DEBUG update_idrange_baserid: search for ipa-ad-trust-posix ID ranges with ipaBaseRID != 0 2018-02-15T06:44:20Z DEBUG update_idrange_baserid: no AD domain range with posix attributes found 2018-02-15T06:44:20Z DEBUG Executing upgrade plugin: update_passync_privilege_update 2018-02-15T06:44:20Z DEBUG raw: update_passync_privilege_update 2018-02-15T06:44:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:20Z DEBUG PassSync privilege update not needed 2018-02-15T06:44:20Z DEBUG Executing upgrade plugin: update_dnsserver_configuration_into_ldap 2018-02-15T06:44:20Z DEBUG raw: update_dnsserver_configuration_into_ldap 2018-02-15T06:44:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:20Z DEBUG raw: server_show(u'replica3.pytest.test', version=u'2.228') 2018-02-15T06:44:20Z DEBUG server_show(u'replica3.pytest.test', rights=False, all=False, raw=False, version=u'2.228', no_members=False) 2018-02-15T06:44:20Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version=u'2.228') 2018-02-15T06:44:20Z DEBUG topologysuffix_find(None, all=True, raw=True, version=u'2.228', pkey_only=False) 2018-02-15T06:44:20Z DEBUG raw: server_role_find(None, server_server=u'replica3.pytest.test', status=u'enabled', version=u'2.228') 2018-02-15T06:44:20Z DEBUG server_role_find(None, server_server=u'replica3.pytest.test', status=u'enabled', all=False, raw=False, version=u'2.228') 2018-02-15T06:44:20Z DEBUG This server is not DNS server, nothing to upgrade 2018-02-15T06:44:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:20Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:20Z DEBUG Executing upgrade plugin: update_ldap_server_list 2018-02-15T06:44:20Z DEBUG raw: update_ldap_server_list 2018-02-15T06:44:20Z DEBUG Executing upgrade plugin: update_dna_shared_config 2018-02-15T06:44:20Z DEBUG raw: update_dna_shared_config 2018-02-15T06:44:20Z DEBUG 2 entries dnaHostname=replica3.pytest.test under cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=pytest,dc=test. One expected 2018-02-15T06:44:20Z DEBUG Destroyed connection context.ldap2_140099962487952 2018-02-15T06:44:20Z DEBUG duration: 73 seconds 2018-02-15T06:44:20Z DEBUG [7/9]: stopping directory server 2018-02-15T06:44:20Z DEBUG Destroyed connection context.ldap2_140100023575440 2018-02-15T06:44:20Z DEBUG Starting external process 2018-02-15T06:44:20Z DEBUG args=/bin/systemctl stop dirsrv@PYTEST-TEST.service 2018-02-15T06:44:26Z DEBUG Process finished, return code=0 2018-02-15T06:44:26Z DEBUG stdout= 2018-02-15T06:44:26Z DEBUG stderr= 2018-02-15T06:44:26Z DEBUG duration: 6 seconds 2018-02-15T06:44:26Z DEBUG [8/9]: restoring configuration 2018-02-15T06:44:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:26Z DEBUG duration: 0 seconds 2018-02-15T06:44:26Z DEBUG [9/9]: starting directory server 2018-02-15T06:44:26Z DEBUG Starting external process 2018-02-15T06:44:26Z DEBUG args=/bin/systemctl start dirsrv@PYTEST-TEST.service 2018-02-15T06:44:31Z DEBUG Process finished, return code=0 2018-02-15T06:44:31Z DEBUG stdout= 2018-02-15T06:44:31Z DEBUG stderr= 2018-02-15T06:44:31Z DEBUG Created connection context.ldap2_140100023575440 2018-02-15T06:44:31Z DEBUG duration: 5 seconds 2018-02-15T06:44:31Z DEBUG Done. 2018-02-15T06:44:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:31Z DEBUG Restarting the KDC 2018-02-15T06:44:31Z DEBUG Starting external process 2018-02-15T06:44:31Z DEBUG args=/bin/systemctl restart krb5kdc.service 2018-02-15T06:44:31Z DEBUG Process finished, return code=0 2018-02-15T06:44:31Z DEBUG stdout= 2018-02-15T06:44:31Z DEBUG stderr= 2018-02-15T06:44:31Z DEBUG Starting external process 2018-02-15T06:44:31Z DEBUG args=/bin/systemctl is-active krb5kdc.service 2018-02-15T06:44:31Z DEBUG Process finished, return code=0 2018-02-15T06:44:31Z DEBUG stdout=active 2018-02-15T06:44:31Z DEBUG stderr= 2018-02-15T06:44:31Z INFO Waiting up to 300 seconds to see our keys appear on host: master.pytest.test 2018-02-15T06:44:31Z DEBUG Starting external process 2018-02-15T06:44:31Z DEBUG args=/bin/systemctl restart sssd.service 2018-02-15T06:44:32Z DEBUG Process finished, return code=0 2018-02-15T06:44:32Z DEBUG stdout= 2018-02-15T06:44:32Z DEBUG stderr= 2018-02-15T06:44:32Z DEBUG Starting external process 2018-02-15T06:44:32Z DEBUG args=/bin/systemctl is-active sssd.service 2018-02-15T06:44:32Z DEBUG Process finished, return code=0 2018-02-15T06:44:32Z DEBUG stdout=active 2018-02-15T06:44:32Z DEBUG stderr= 2018-02-15T06:44:32Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:44:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket from SchemaCache 2018-02-15T06:44:32Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-PYTEST-TEST.socket conn= 2018-02-15T06:44:32Z DEBUG Starting external process 2018-02-15T06:44:32Z DEBUG args=/bin/systemctl stop named-pkcs11.service 2018-02-15T06:44:32Z DEBUG Process finished, return code=0 2018-02-15T06:44:32Z DEBUG stdout= 2018-02-15T06:44:32Z DEBUG stderr= 2018-02-15T06:44:32Z DEBUG raw: dnszone_show(u'pytest.test', version=u'2.228') 2018-02-15T06:44:32Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:32Z DEBUG Configuring DNS (named) 2018-02-15T06:44:32Z DEBUG [1/8]: generating rndc key file 2018-02-15T06:44:32Z DEBUG Starting external process 2018-02-15T06:44:32Z DEBUG args=/usr/libexec/generate-rndc-key.sh 2018-02-15T06:44:32Z DEBUG Process finished, return code=0 2018-02-15T06:44:32Z DEBUG stdout= 2018-02-15T06:44:32Z DEBUG stderr= 2018-02-15T06:44:32Z DEBUG duration: 0 seconds 2018-02-15T06:44:32Z DEBUG [2/8]: setting up our own record 2018-02-15T06:44:32Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:32Z DEBUG duration: 0 seconds 2018-02-15T06:44:32Z DEBUG [3/8]: adding NS record to the zones 2018-02-15T06:44:32Z DEBUG raw: dnszone_find(None, version=u'2.228') 2018-02-15T06:44:32Z DEBUG dnszone_find(None, forward_only=False, all=False, raw=False, version=u'2.228', pkey_only=False) 2018-02-15T06:44:32Z DEBUG adding self NS to zone pytest.test. apex 2018-02-15T06:44:32Z DEBUG raw: dnsrecord_add(u'pytest.test.', u'@', nsrecord=u'replica3.pytest.test.', force=True, version=u'2.228') 2018-02-15T06:44:32Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, nsrecord=(u'replica3.pytest.test.',), force=True, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG duration: 0 seconds 2018-02-15T06:44:32Z DEBUG [4/8]: setting up kerberos principal 2018-02-15T06:44:32Z DEBUG Starting external process 2018-02-15T06:44:32Z DEBUG args=kadmin.local -q addprinc -randkey DNS/replica3.pytest.test@PYTEST.TEST -x ipa-setup-override-restrictions 2018-02-15T06:44:32Z DEBUG Process finished, return code=0 2018-02-15T06:44:32Z DEBUG stdout=Authenticating as principal host/admin@PYTEST.TEST with password. Principal "DNS/replica3.pytest.test@PYTEST.TEST" created. 2018-02-15T06:44:32Z DEBUG stderr=WARNING: no policy specified for DNS/replica3.pytest.test@PYTEST.TEST; defaulting to no policy 2018-02-15T06:44:32Z DEBUG Backing up system configuration file '/etc/named.keytab' 2018-02-15T06:44:32Z DEBUG -> Not backing up - '/etc/named.keytab' doesn't exist 2018-02-15T06:44:32Z DEBUG Starting external process 2018-02-15T06:44:32Z DEBUG args=kadmin.local -q ktadd -k /etc/named.keytab DNS/replica3.pytest.test@PYTEST.TEST -x ipa-setup-override-restrictions 2018-02-15T06:44:32Z DEBUG Process finished, return code=0 2018-02-15T06:44:32Z DEBUG stdout=Authenticating as principal host/admin@PYTEST.TEST with password. Entry for principal DNS/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type des3-cbc-sha1 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type arcfour-hmac added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/named.keytab. 2018-02-15T06:44:32Z DEBUG stderr= 2018-02-15T06:44:32Z DEBUG duration: 0 seconds 2018-02-15T06:44:32Z DEBUG [5/8]: setting up named.conf 2018-02-15T06:44:32Z DEBUG Backing up system configuration file '/etc/named.conf' 2018-02-15T06:44:32Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:44:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:32Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:32Z DEBUG duration: 0 seconds 2018-02-15T06:44:32Z DEBUG [6/8]: setting up server configuration 2018-02-15T06:44:32Z DEBUG raw: dnsserver_add(u'replica3.pytest.test', idnssoamname=, version=u'2.228') 2018-02-15T06:44:32Z DEBUG dnsserver_add(u'replica3.pytest.test', idnssoamname=, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:32Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2018-02-15T06:44:32Z DEBUG duration: 0 seconds 2018-02-15T06:44:32Z DEBUG [7/8]: configuring named to start on boot 2018-02-15T06:44:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG Starting external process 2018-02-15T06:44:32Z DEBUG args=/bin/systemctl is-active named-pkcs11.service 2018-02-15T06:44:32Z DEBUG Process finished, return code=3 2018-02-15T06:44:32Z DEBUG stdout=unknown 2018-02-15T06:44:32Z DEBUG stderr= 2018-02-15T06:44:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG Starting external process 2018-02-15T06:44:32Z DEBUG args=/bin/systemctl is-active named.service 2018-02-15T06:44:32Z DEBUG Process finished, return code=3 2018-02-15T06:44:32Z DEBUG stdout=unknown 2018-02-15T06:44:32Z DEBUG stderr= 2018-02-15T06:44:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG Starting external process 2018-02-15T06:44:32Z DEBUG args=/bin/systemctl disable named-pkcs11.service 2018-02-15T06:44:32Z DEBUG Process finished, return code=0 2018-02-15T06:44:32Z DEBUG stdout= 2018-02-15T06:44:32Z DEBUG stderr= 2018-02-15T06:44:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:32Z DEBUG Starting external process 2018-02-15T06:44:32Z DEBUG args=/bin/systemctl is-active named.service 2018-02-15T06:44:33Z DEBUG Process finished, return code=3 2018-02-15T06:44:33Z DEBUG stdout=unknown 2018-02-15T06:44:33Z DEBUG stderr= 2018-02-15T06:44:33Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:33Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:33Z DEBUG Starting external process 2018-02-15T06:44:33Z DEBUG args=/bin/systemctl stop named.service 2018-02-15T06:44:33Z DEBUG Process finished, return code=0 2018-02-15T06:44:33Z DEBUG stdout= 2018-02-15T06:44:33Z DEBUG stderr= 2018-02-15T06:44:33Z DEBUG Starting external process 2018-02-15T06:44:33Z DEBUG args=/bin/systemctl mask named.service 2018-02-15T06:44:33Z DEBUG Process finished, return code=0 2018-02-15T06:44:33Z DEBUG stdout= 2018-02-15T06:44:33Z DEBUG stderr=Created symlink from /etc/systemd/system/named.service to /dev/null. 2018-02-15T06:44:33Z DEBUG duration: 0 seconds 2018-02-15T06:44:33Z DEBUG [8/8]: changing resolv.conf to point to ourselves 2018-02-15T06:44:33Z DEBUG Backing up system configuration file '/etc/resolv.conf' 2018-02-15T06:44:33Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:44:33Z DEBUG duration: 0 seconds 2018-02-15T06:44:33Z DEBUG Done configuring DNS (named). 2018-02-15T06:44:33Z DEBUG Starting external process 2018-02-15T06:44:33Z DEBUG args=/bin/systemctl restart httpd.service 2018-02-15T06:44:35Z DEBUG Process finished, return code=0 2018-02-15T06:44:35Z DEBUG stdout= 2018-02-15T06:44:35Z DEBUG stderr= 2018-02-15T06:44:35Z DEBUG Starting external process 2018-02-15T06:44:35Z DEBUG args=/bin/systemctl is-active httpd.service 2018-02-15T06:44:35Z DEBUG Process finished, return code=0 2018-02-15T06:44:35Z DEBUG stdout=active 2018-02-15T06:44:35Z DEBUG stderr= 2018-02-15T06:44:35Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:35Z DEBUG Starting external process 2018-02-15T06:44:35Z DEBUG args=/bin/systemctl stop ipa-dnskeysyncd.service 2018-02-15T06:44:35Z DEBUG Process finished, return code=0 2018-02-15T06:44:35Z DEBUG stdout= 2018-02-15T06:44:35Z DEBUG stderr= 2018-02-15T06:44:35Z DEBUG Configuring DNS key synchronization service (ipa-dnskeysyncd) 2018-02-15T06:44:35Z DEBUG [1/7]: checking status 2018-02-15T06:44:35Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:35Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:35Z DEBUG duration: 0 seconds 2018-02-15T06:44:35Z DEBUG [2/7]: setting up bind-dyndb-ldap working directory 2018-02-15T06:44:35Z DEBUG duration: 0 seconds 2018-02-15T06:44:35Z DEBUG [3/7]: setting up kerberos principal 2018-02-15T06:44:35Z DEBUG Removing service keytab: /etc/ipa/dnssec/ipa-dnskeysyncd.keytab 2018-02-15T06:44:35Z DEBUG Starting external process 2018-02-15T06:44:35Z DEBUG args=kadmin.local -q addprinc -randkey ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST -x ipa-setup-override-restrictions 2018-02-15T06:44:36Z DEBUG Process finished, return code=0 2018-02-15T06:44:36Z DEBUG stdout=Authenticating as principal host/admin@PYTEST.TEST with password. Principal "ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST" created. 2018-02-15T06:44:36Z DEBUG stderr=WARNING: no policy specified for ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST; defaulting to no policy 2018-02-15T06:44:36Z DEBUG Starting external process 2018-02-15T06:44:36Z DEBUG args=kadmin.local -q ktadd -k /etc/ipa/dnssec/ipa-dnskeysyncd.keytab ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST -x ipa-setup-override-restrictions 2018-02-15T06:44:36Z DEBUG Process finished, return code=0 2018-02-15T06:44:36Z DEBUG stdout=Authenticating as principal host/admin@PYTEST.TEST with password. Entry for principal ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type des3-cbc-sha1 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type arcfour-hmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/replica3.pytest.test@PYTEST.TEST with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. 2018-02-15T06:44:36Z DEBUG stderr= 2018-02-15T06:44:37Z DEBUG duration: 1 seconds 2018-02-15T06:44:37Z DEBUG [4/7]: setting up SoftHSM 2018-02-15T06:44:37Z DEBUG Creating new softhsm config file 2018-02-15T06:44:37Z DEBUG Backing up system configuration file '/etc/sysconfig/named' 2018-02-15T06:44:37Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2018-02-15T06:44:37Z DEBUG Removing old tokens directory /var/lib/ipa/dnssec/tokens 2018-02-15T06:44:37Z DEBUG Creating tokens /var/lib/ipa/dnssec/tokens directory 2018-02-15T06:44:37Z DEBUG Saving user PIN to /var/lib/ipa/dnssec/softhsm_pin 2018-02-15T06:44:37Z DEBUG Saving SO PIN to /etc/ipa/dnssec/softhsm_pin_so 2018-02-15T06:44:37Z DEBUG Initializing tokens 2018-02-15T06:44:37Z DEBUG Starting external process 2018-02-15T06:44:37Z DEBUG args=/usr/bin/softhsm2-util --init-token --free --label ipaDNSSEC --pin XXXXXXXX --so-pin XXXXXXXX 2018-02-15T06:44:37Z DEBUG Process finished, return code=0 2018-02-15T06:44:37Z DEBUG stdout=Token 0 is free. The token has been initialized. 2018-02-15T06:44:37Z DEBUG stderr= 2018-02-15T06:44:37Z DEBUG duration: 0 seconds 2018-02-15T06:44:37Z DEBUG [5/7]: adding DNSSEC containers 2018-02-15T06:44:37Z INFO DNSSEC container exists (step skipped) 2018-02-15T06:44:37Z DEBUG duration: 0 seconds 2018-02-15T06:44:37Z DEBUG [6/7]: creating replica keys 2018-02-15T06:44:37Z DEBUG Creating replica's key pair 2018-02-15T06:44:37Z DEBUG Storing replica public key to LDAP, ipk11UniqueId=autogenerate,cn=keys,cn=sec,cn=dns,dc=pytest,dc=test 2018-02-15T06:44:38Z DEBUG Replica public key stored 2018-02-15T06:44:38Z DEBUG Setting CKA_WRAP=False for old replica keys 2018-02-15T06:44:38Z DEBUG Changing ownership of token files 2018-02-15T06:44:38Z DEBUG duration: 0 seconds 2018-02-15T06:44:38Z DEBUG [7/7]: configuring ipa-dnskeysyncd to start on boot 2018-02-15T06:44:38Z DEBUG Starting external process 2018-02-15T06:44:38Z DEBUG args=/bin/systemctl disable ipa-dnskeysyncd.service 2018-02-15T06:44:38Z DEBUG Process finished, return code=0 2018-02-15T06:44:38Z DEBUG stdout= 2018-02-15T06:44:38Z DEBUG stderr= 2018-02-15T06:44:38Z DEBUG duration: 0 seconds 2018-02-15T06:44:38Z DEBUG Done configuring DNS key synchronization service (ipa-dnskeysyncd). 2018-02-15T06:44:38Z DEBUG Starting external process 2018-02-15T06:44:38Z DEBUG args=/bin/systemctl restart ipa-dnskeysyncd.service 2018-02-15T06:44:38Z DEBUG Process finished, return code=0 2018-02-15T06:44:38Z DEBUG stdout= 2018-02-15T06:44:38Z DEBUG stderr= 2018-02-15T06:44:38Z DEBUG Starting external process 2018-02-15T06:44:38Z DEBUG args=/bin/systemctl is-active ipa-dnskeysyncd.service 2018-02-15T06:44:38Z DEBUG Process finished, return code=0 2018-02-15T06:44:38Z DEBUG stdout=active 2018-02-15T06:44:38Z DEBUG stderr= 2018-02-15T06:44:38Z DEBUG Restarting named 2018-02-15T06:44:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:38Z DEBUG Starting external process 2018-02-15T06:44:38Z DEBUG args=/bin/systemctl is-active named-pkcs11.service 2018-02-15T06:44:38Z DEBUG Process finished, return code=3 2018-02-15T06:44:38Z DEBUG stdout=unknown 2018-02-15T06:44:38Z DEBUG stderr= 2018-02-15T06:44:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2018-02-15T06:44:38Z DEBUG Starting external process 2018-02-15T06:44:38Z DEBUG args=/bin/systemctl restart named-pkcs11.service 2018-02-15T06:44:38Z DEBUG Process finished, return code=0 2018-02-15T06:44:38Z DEBUG stdout= 2018-02-15T06:44:38Z DEBUG stderr= 2018-02-15T06:44:38Z DEBUG Starting external process 2018-02-15T06:44:38Z DEBUG args=/bin/systemctl is-active named-pkcs11.service 2018-02-15T06:44:38Z DEBUG Process finished, return code=0 2018-02-15T06:44:38Z DEBUG stdout=active 2018-02-15T06:44:38Z DEBUG stderr= 2018-02-15T06:44:38Z DEBUG Updating DNS system records 2018-02-15T06:44:38Z DEBUG raw: server_find(None, version=u'2.228', no_members=False) 2018-02-15T06:44:38Z DEBUG server_find(None, all=False, raw=False, version=u'2.228', no_members=False, pkey_only=False) 2018-02-15T06:44:38Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version=u'2.228') 2018-02-15T06:44:38Z DEBUG topologysuffix_find(None, all=True, raw=True, version=u'2.228', pkey_only=False) 2018-02-15T06:44:38Z DEBUG raw: server_role_find(None, server_server=u'master.pytest.test', status=u'enabled', version=u'2.228') 2018-02-15T06:44:38Z DEBUG server_role_find(None, server_server=u'master.pytest.test', status=u'enabled', all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: server_role_find(None, server_server=u'replica.pytest.test', status=u'enabled', version=u'2.228') 2018-02-15T06:44:38Z DEBUG server_role_find(None, server_server=u'replica.pytest.test', status=u'enabled', all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: server_role_find(None, server_server=u'replica3.pytest.test', status=u'enabled', version=u'2.228') 2018-02-15T06:44:38Z DEBUG server_role_find(None, server_server=u'replica3.pytest.test', status=u'enabled', all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnszone_show(, version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 88 replica3.pytest.test.', u'0 100 88 replica.pytest.test.', u'0 100 88 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 88 replica3.pytest.test.', u'0 100 88 replica.pytest.test.', u'0 100 88 master.pytest.test.'), setattr=(u'idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 464 replica3.pytest.test.', u'0 100 464 replica.pytest.test.', u'0 100 464 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 464 replica3.pytest.test.', u'0 100 464 replica.pytest.test.', u'0 100 464 master.pytest.test.'), setattr=(u'idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 88 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 88 master.pytest.test.',), setattr=(u'idnsTemplateAttribute;cnamerecord=_kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 389 replica3.pytest.test.', u'0 100 389 replica.pytest.test.', u'0 100 389 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 389 replica3.pytest.test.', u'0 100 389 replica.pytest.test.', u'0 100 389 master.pytest.test.'), setattr=(u'idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 464 replica3.pytest.test.', u'0 100 464 replica.pytest.test.', u'0 100 464 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 464 replica3.pytest.test.', u'0 100 464 replica.pytest.test.', u'0 100 464 master.pytest.test.'), setattr=(u'idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 389 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 389 master.pytest.test.',), setattr=(u'idnsTemplateAttribute;cnamerecord=_ldap._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 88 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 88 master.pytest.test.',), setattr=(u'idnsTemplateAttribute;cnamerecord=_kerberos._tcp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 123 replica3.pytest.test.', u'0 100 123 replica.pytest.test.', u'0 100 123 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_ntp._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 123 replica3.pytest.test.', u'0 100 123 replica.pytest.test.', u'0 100 123 master.pytest.test.'), setattr=(u'idnsTemplateAttribute;cnamerecord=_ntp._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , txtrecord=[u'"PYTEST.TEST"'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , txtrecord=(u'"PYTEST.TEST"',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 88 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 88 master.pytest.test.',), setattr=(u'idnsTemplateAttribute;cnamerecord=_kerberos._udp.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 88 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 88 master.pytest.test.',), setattr=(u'idnsTemplateAttribute;cnamerecord=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 88 replica3.pytest.test.', u'0 100 88 replica.pytest.test.', u'0 100 88 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 88 replica3.pytest.test.', u'0 100 88 replica.pytest.test.', u'0 100 88 master.pytest.test.'), setattr=(u'idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:38Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 88 replica3.pytest.test.', u'0 100 88 replica.pytest.test.', u'0 100 88 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:38Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 88 replica3.pytest.test.', u'0 100 88 replica.pytest.test.', u'0 100 88 master.pytest.test.'), setattr=(u'idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'0 100 88 replica3.pytest.test.', u'0 100 88 replica.pytest.test.', u'0 100 88 master.pytest.test.'], setattr=[u'idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=[u'objectclass=idnsTemplateObject'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'0 100 88 replica3.pytest.test.', u'0 100 88 replica.pytest.test.', u'0 100 88 master.pytest.test.'), setattr=(u'idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=(u'objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: server_find(None, version=u'2.228', pkey_only=True) 2018-02-15T06:44:39Z DEBUG server_find(None, all=False, raw=False, version=u'2.228', no_members=True, pkey_only=True) 2018-02-15T06:44:39Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version=u'2.228') 2018-02-15T06:44:39Z DEBUG topologysuffix_find(None, all=True, raw=True, version=u'2.228', pkey_only=False) 2018-02-15T06:44:39Z DEBUG raw: location_find(None, version=u'2.228') 2018-02-15T06:44:39Z DEBUG location_find(None, all=False, raw=False, version=u'2.228', pkey_only=False) 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 464 master.pytest.test.', u'50 100 464 replica.pytest.test.', u'50 100 464 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 464 master.pytest.test.', u'50 100 464 replica.pytest.test.', u'50 100 464 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 389 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 389 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 123 master.pytest.test.', u'50 100 123 replica.pytest.test.', u'50 100 123 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 123 master.pytest.test.', u'50 100 123 replica.pytest.test.', u'50 100 123 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 389 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 389 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 464 master.pytest.test.', u'50 100 464 replica.pytest.test.', u'50 100 464 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 464 master.pytest.test.', u'50 100 464 replica.pytest.test.', u'50 100 464 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 123 master.pytest.test.', u'50 100 123 replica.pytest.test.', u'50 100 123 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 123 master.pytest.test.', u'50 100 123 replica.pytest.test.', u'50 100 123 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 389 master.pytest.test.', u'50 100 389 replica.pytest.test.', u'50 100 389 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 389 master.pytest.test.', u'50 100 389 replica.pytest.test.', u'50 100 389 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 464 master.pytest.test.', u'50 100 464 replica.pytest.test.', u'50 100 464 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 464 master.pytest.test.', u'50 100 464 replica.pytest.test.', u'50 100 464 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.', u'50 100 88 replica.pytest.test.', u'50 100 88 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 464 master.pytest.test.', u'50 100 464 replica.pytest.test.', u'50 100 464 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 464 master.pytest.test.', u'50 100 464 replica.pytest.test.', u'50 100 464 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 88 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 88 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 389 master.pytest.test.', u'50 100 389 replica.pytest.test.', u'50 100 389 replica3.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 389 master.pytest.test.', u'50 100 389 replica.pytest.test.', u'50 100 389 replica3.pytest.test.'), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 389 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 389 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsrecord_mod(, , srvrecord=[u'50 100 389 master.pytest.test.'], version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsrecord_mod(, , srvrecord=(u'50 100 389 master.pytest.test.',), rights=False, structured=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG raw: dnsconfig_show(version=u'2.228') 2018-02-15T06:44:39Z DEBUG dnsconfig_show(rights=False, all=False, raw=False, version=u'2.228') 2018-02-15T06:44:39Z DEBUG Destroyed connection context.ldap2_140100023575440 2018-02-15T06:44:39Z DEBUG Starting external process 2018-02-15T06:44:39Z DEBUG args=/bin/systemctl enable ipa.service 2018-02-15T06:44:39Z DEBUG Process finished, return code=0 2018-02-15T06:44:39Z DEBUG stdout= 2018-02-15T06:44:39Z DEBUG stderr=Created symlink from /etc/systemd/system/multi-user.target.wants/ipa.service to /usr/lib/systemd/system/ipa.service. 2018-02-15T06:44:39Z DEBUG Starting external process 2018-02-15T06:44:39Z DEBUG args=/bin/systemctl restart ipa.service 2018-02-15T06:44:42Z DEBUG Process finished, return code=0 2018-02-15T06:44:42Z DEBUG stdout= 2018-02-15T06:44:42Z DEBUG stderr= 2018-02-15T06:44:42Z DEBUG Starting external process 2018-02-15T06:44:42Z DEBUG args=/bin/systemctl is-active ipa.service 2018-02-15T06:44:42Z DEBUG Process finished, return code=0 2018-02-15T06:44:42Z DEBUG stdout=active 2018-02-15T06:44:42Z DEBUG stderr= 2018-02-15T06:44:42Z INFO The ipa-replica-install command was successful