2024-03-08T12:32:40Z INFO IPA to IPA migration starting ... 2024-03-08T12:32:40Z DEBUG Migration options: 2024-03-08T12:32:40Z DEBUG --mode=prod-mode 2024-03-08T12:32:40Z DEBUG --hostname=server2.testrelm.test 2024-03-08T12:32:40Z DEBUG --verbose=False 2024-03-08T12:32:40Z DEBUG --bind-dn=cn=Directory Manager 2024-03-08T12:32:40Z DEBUG --bind-pw-file=None 2024-03-08T12:32:40Z DEBUG --cacertfile=None 2024-03-08T12:32:40Z DEBUG --subtree=[] 2024-03-08T12:32:40Z DEBUG --log-file=/var/log/ipa-migrate.log 2024-03-08T12:32:40Z DEBUG --skip-schema=False 2024-03-08T12:32:40Z DEBUG --skip-config=False 2024-03-08T12:32:40Z DEBUG --skip-dns=False 2024-03-08T12:32:40Z DEBUG --dryrun=False 2024-03-08T12:32:40Z DEBUG --dryrun-record=None 2024-03-08T12:32:40Z DEBUG --force=False 2024-03-08T12:32:40Z DEBUG --version=False 2024-03-08T12:32:40Z DEBUG --quiet=False 2024-03-08T12:32:40Z DEBUG --schema-overwrite=False 2024-03-08T12:32:40Z DEBUG --reset-range=False 2024-03-08T12:32:40Z DEBUG --db-ldif=None 2024-03-08T12:32:40Z DEBUG --schema-ldif=None 2024-03-08T12:32:40Z DEBUG --config-ldif=None 2024-03-08T12:32:40Z DEBUG --no-prompt=False 2024-03-08T12:32:40Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2024-03-08T12:32:40Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2024-03-08T12:32:41Z DEBUG retrieving schema for SchemaCache url=ldap://server2.testrelm.test conn= 2024-03-08T12:32:41Z DEBUG update_entry modlist [(2, 'ipamigrationenabled', [b'TRUE'])] 2024-03-08T12:32:41Z DEBUG Found realm from remote server: TESTRELM.TEST 2024-03-08T12:32:41Z INFO Migrating schema ... 2024-03-08T12:32:41Z DEBUG Getting schema from the remote server ... 2024-03-08T12:32:41Z DEBUG Retrieved 1537 attributes and 343 objectClasses 2024-03-08T12:32:43Z DEBUG Migrated 0 attributes and 0 objectClasses 2024-03-08T12:32:43Z DEBUG Skipped 1537 attributes and 343 objectClasses 2024-03-08T12:32:43Z INFO Migrating configuration ... 2024-03-08T12:32:43Z DEBUG Getting config from the remote server ... 2024-03-08T12:32:43Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2024-03-08T12:32:43Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2024-03-08T12:32:43Z DEBUG Config setting 'dnaMaxValue' replaced '['9599999']' with '1758599999' in 'cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config' 2024-03-08T12:32:43Z DEBUG Config setting 'dnaNextValue' replaced '['9400004']' with '1758400002' in 'cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config' 2024-03-08T12:32:43Z DEBUG update_entry modlist [(2, 'dnaNextValue', [b'1758400002']), (2, 'dnaMaxValue', [b'1758599999'])] 2024-03-08T12:32:43Z INFO Migrating database ... (this make take a while) 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'uid=admin,cn=users,cn=accounts,dc=ipa,dc=test' attribute 'uidNumber' replaced with val '1758400000' old value: ['9400000'] 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'uid=admin,cn=users,cn=accounts,dc=ipa,dc=test' attribute 'gidNumber' replaced with val '1758400000' old value: ['9400000'] 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'uid=admin,cn=users,cn=accounts,dc=ipa,dc=test' attribute 'ipaNTSecurityIdentifier' replaced with val 'S-1-5-21-703463177-928160953-153386150-500' old value: ['S-1-5-21-937587600-1674369763-71644707-500'] 2024-03-08T12:32:43Z DEBUG update_entry modlist [(2, 'gidNumber', [b'1758400000']), (2, 'ipaNTSecurityIdentifier', [b'S-1-5-21-703463177-928160953-153386150-500']), (2, 'uidNumber', [b'1758400000'])] 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test' attribute 'gidNumber' replaced with val '1758400000' old value: ['9400000'] 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test' attribute 'ipaNTSecurityIdentifier' replaced with val 'S-1-5-21-703463177-928160953-153386150-512' old value: ['S-1-5-21-937587600-1674369763-71644707-512'] 2024-03-08T12:32:43Z DEBUG update_entry modlist [(2, 'gidNumber', [b'1758400000']), (2, 'ipaNTSecurityIdentifier', [b'S-1-5-21-703463177-928160953-153386150-512'])] 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'cn=editors,cn=groups,cn=accounts,dc=ipa,dc=test' attribute 'gidNumber' replaced with val '1758400002' old value: ['9400002'] 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'cn=editors,cn=groups,cn=accounts,dc=ipa,dc=test' attribute 'ipaNTSecurityIdentifier' replaced with val 'S-1-5-21-703463177-928160953-153386150-1002' old value: ['S-1-5-21-937587600-1674369763-71644707-1002'] 2024-03-08T12:32:43Z DEBUG update_entry modlist [(2, 'gidNumber', [b'1758400002']), (2, 'ipaNTSecurityIdentifier', [b'S-1-5-21-703463177-928160953-153386150-1002'])] 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'cn=IPA.TEST_id_range,cn=ranges,cn=etc,dc=ipa,dc=test' attribute 'ipaBaseID' replaced with val '1758400000' old value: ['9400000'] 2024-03-08T12:32:43Z DEBUG update_entry modlist [(2, 'ipaBaseID', [b'1758400000'])] 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'cn=IPA.TEST_subid_range,cn=ranges,cn=etc,dc=ipa,dc=test' attribute 'ipaNTTrustedDomainSID' replaced with val 'S-1-5-21-738065-838566-1333733278' old value: ['S-1-5-21-738065-838566-3693636073'] 2024-03-08T12:32:43Z DEBUG update_entry modlist [(2, 'ipaNTTrustedDomainSID', [b'S-1-5-21-738065-838566-1333733278'])] 2024-03-08T12:32:43Z DEBUG Entry is different and will be updated: 'uid=sudo,cn=sysaccounts,cn=etc,dc=ipa,dc=test' attribute 'userPassword' add val '{PBKDF2-SHA512}10000$fVBzRPh3rNOqVqfHkxZbE9ZsiJG8gTy+$UzJWyPfnDHV/UY2A/oKy21riDhgxbBmYLyEG4Jsfbj5g/BocI0ATJLCHrkPue55TjcpA+DeLfdPR6AN6Ok4tpw==' not in ['{PBKDF2-SHA512}10000$nQmMYnGeo25MGLbZljTWvHKp4dwyJK1j$KfXP0hGGvcnDZy5J33b+Vd59Fch9aU7p2BpgNnFmuX1JRLKdYITSiX+8+pboCLo6DdTtPGo9Y6iCoFJICMwxJw=='] 2024-03-08T12:32:43Z DEBUG update_entry modlist [(0, 'userPassword', [b'{PBKDF2-SHA512}10000$fVBzRPh3rNOqVqfHkxZbE9ZsiJG8gTy+$UzJWyPfnDHV/UY2A/oKy21riDhgxbBmYLyEG4Jsfbj5g/BocI0ATJLCHrkPue55TjcpA+DeLfdPR6AN6Ok4tpw=='])] 2024-03-08T12:32:43Z DEBUG Removed IPA issued userCertificate from: krbprincipalname=ldap/server2.testrelm.test@TESTRELM.TEST,cn=services,cn=accounts,dc=testrelm,dc=test 2024-03-08T12:32:44Z DEBUG Skipping remote certificate entry: 'cn=TESTRELM.TEST IPA CA,cn=certificates,cn=ipa,cn=etc,dc=testrelm,dc=test' Issuer: CN=Certificate Authority,O=TESTRELM.TEST 2024-03-08T12:32:44Z DEBUG Removed IPA issued userCertificate from: krbprincipalname=HTTP/server2.testrelm.test@TESTRELM.TEST,cn=services,cn=accounts,dc=testrelm,dc=test 2024-03-08T12:32:44Z DEBUG Entry is different and will be updated: 'cn=ipa.test,cn=ad,cn=etc,dc=ipa,dc=test' attribute 'ipaNTSecurityIdentifier' replaced with val 'S-1-5-21-703463177-928160953-153386150' old value: ['S-1-5-21-937587600-1674369763-71644707'] 2024-03-08T12:32:44Z DEBUG Entry is different and will be updated: 'cn=ipa.test,cn=ad,cn=etc,dc=ipa,dc=test' attribute 'ipaNTDomainGUID' replaced with val '17775b9d-02e9-4a24-a0f3-c27f6a4217f2' old value: ['e75fc7a0-94f8-4ccd-9218-c2b4dde927ef'] 2024-03-08T12:32:44Z DEBUG update_entry modlist [(2, 'ipaNTSecurityIdentifier', [b'S-1-5-21-703463177-928160953-153386150']), (2, 'ipaNTDomainGUID', [b'17775b9d-02e9-4a24-a0f3-c27f6a4217f2'])] 2024-03-08T12:32:44Z DEBUG Entry is different and will be updated: 'cn=Default SMB Group,cn=groups,cn=accounts,dc=ipa,dc=test' attribute 'gidNumber' replaced with val '1758400001' old value: ['9400001'] 2024-03-08T12:32:44Z DEBUG Entry is different and will be updated: 'cn=Default SMB Group,cn=groups,cn=accounts,dc=ipa,dc=test' attribute 'ipaNTSecurityIdentifier' replaced with val 'S-1-5-21-703463177-928160953-153386150-1001' old value: ['S-1-5-21-937587600-1674369763-71644707-1001'] 2024-03-08T12:32:44Z DEBUG update_entry modlist [(2, 'gidNumber', [b'1758400001']), (2, 'ipaNTSecurityIdentifier', [b'S-1-5-21-703463177-928160953-153386150-1001'])] 2024-03-08T12:32:44Z INFO Running ipa-server-upgrade ... (this make take a while) 2024-03-08T12:32:46Z DEBUG Upgrading IPA:. Estimated time: 1 minute 30 seconds 2024-03-08T12:32:46Z DEBUG [1/11]: stopping directory server 2024-03-08T12:32:48Z DEBUG [2/11]: saving configuration 2024-03-08T12:32:48Z DEBUG [3/11]: disabling listeners 2024-03-08T12:32:48Z DEBUG [4/11]: enabling DS global lock 2024-03-08T12:32:48Z DEBUG [5/11]: disabling Schema Compat 2024-03-08T12:32:48Z DEBUG [6/11]: starting directory server 2024-03-08T12:32:49Z DEBUG [7/11]: updating schema 2024-03-08T12:32:52Z DEBUG [8/11]: upgrading server 2024-03-08T12:32:57Z DEBUG [9/11]: stopping directory server 2024-03-08T12:32:59Z DEBUG [10/11]: restoring configuration 2024-03-08T12:32:59Z DEBUG [11/11]: starting directory server 2024-03-08T12:33:00Z DEBUG Done. 2024-03-08T12:33:38Z DEBUG Upgrading IPA services 2024-03-08T12:33:38Z DEBUG Disabled p11-kit-proxy 2024-03-08T12:33:38Z DEBUG Update complete 2024-03-08T12:33:38Z DEBUG Upgrading the configuration of the IPA services 2024-03-08T12:33:38Z DEBUG [Verifying that root certificate is published] 2024-03-08T12:33:38Z DEBUG [Migrate CRL publish directory] 2024-03-08T12:33:38Z DEBUG Publish directory already set to new location 2024-03-08T12:33:38Z DEBUG [Verifying that KDC configuration is using ipa-kdb backend] 2024-03-08T12:33:38Z DEBUG [Fix DS schema file syntax] 2024-03-08T12:33:38Z DEBUG [Removing RA cert from DS NSS database] 2024-03-08T12:33:38Z DEBUG [Enable sidgen and extdom plugins by default] 2024-03-08T12:33:38Z DEBUG [Updating HTTPD service IPA configuration] 2024-03-08T12:33:38Z DEBUG [Updating HTTPD service IPA WSGI configuration] 2024-03-08T12:33:38Z DEBUG [Migrating from mod_nss to mod_ssl] 2024-03-08T12:33:38Z DEBUG Already migrated to mod_ssl 2024-03-08T12:33:38Z DEBUG [Moving HTTPD service keytab to gssproxy] 2024-03-08T12:33:38Z DEBUG [Removing self-signed CA] 2024-03-08T12:33:38Z DEBUG [Removing Dogtag 9 CA] 2024-03-08T12:33:38Z DEBUG [Checking for deprecated KDC configuration files] 2024-03-08T12:33:38Z DEBUG [Checking for deprecated backups of Samba configuration files] 2024-03-08T12:33:38Z DEBUG dnssec-validation yes 2024-03-08T12:33:38Z DEBUG [Add missing CA DNS records] 2024-03-08T12:33:38Z DEBUG DNS is not configured 2024-03-08T12:33:38Z DEBUG DNS service is not configured 2024-03-08T12:33:38Z DEBUG [Upgrading CA schema] 2024-03-08T12:33:38Z DEBUG CA schema update complete 2024-03-08T12:33:38Z DEBUG [Update certmonger certificate renewal configuration] 2024-03-08T12:33:38Z DEBUG Certmonger certificate renewal configuration already up-to-date 2024-03-08T12:33:38Z DEBUG [Enable PKIX certificate path discovery and validation] 2024-03-08T12:33:38Z DEBUG [Authorizing RA Agent to modify profiles] 2024-03-08T12:33:38Z DEBUG [Authorizing RA Agent to manage lightweight CAs] 2024-03-08T12:33:38Z DEBUG [Ensuring Lightweight CAs container exists in Dogtag database] 2024-03-08T12:33:38Z DEBUG [Enabling LWCA monitor] 2024-03-08T12:33:38Z DEBUG [Adding default OCSP URI configuration] 2024-03-08T12:33:38Z DEBUG [Disabling cert publishing] 2024-03-08T12:33:38Z DEBUG pki-tomcat configuration changed, restart pki-tomcat 2024-03-08T12:33:38Z DEBUG [Ensuring CA is using LDAPProfileSubsystem] 2024-03-08T12:33:38Z DEBUG [Migrating certificate profiles to LDAP] 2024-03-08T12:33:38Z DEBUG [Ensuring presence of included profiles] 2024-03-08T12:33:38Z DEBUG [Add default CA ACL] 2024-03-08T12:33:38Z DEBUG [Updating ACME configuration] 2024-03-08T12:33:38Z DEBUG [Migrating to authselect profile] 2024-03-08T12:33:38Z DEBUG [Create systemd-user hbac service and rule] 2024-03-08T12:33:38Z DEBUG hbac service systemd-user already exists 2024-03-08T12:33:38Z DEBUG [Add root@IPA.TEST alias to admin account] 2024-03-08T12:33:38Z DEBUG Alias already exists 2024-03-08T12:33:38Z DEBUG [Setup SPAKE] 2024-03-08T12:33:38Z DEBUG [Setup PKINIT] 2024-03-08T12:33:38Z DEBUG [Enable server krb5.conf snippet] 2024-03-08T12:33:38Z DEBUG [Setup kpasswd_server] 2024-03-08T12:33:38Z DEBUG [Adding ipa-ca alias to HTTP certificate] 2024-03-08T12:33:38Z DEBUG Certificate is OK; nothing to do 2024-03-08T12:33:38Z DEBUG The IPA services were upgraded 2024-03-08T12:33:38Z DEBUG The ipa-server-upgrade command was successful 2024-03-08T12:33:38Z INFO Running SIDGEN task ... 2024-03-08T12:34:05Z ERROR SIDGEN task failed: Command '['/usr/bin/ipa config-mod --enable-sid --add-sids']' returned non-zero exit status 1. 2024-03-08T12:34:05Z INFO Migration complete! 2024-03-08T12:34:05Z INFO Summary: 2024-03-08T12:34:05Z INFO Summary: 2024-03-08T12:34:05Z INFO =============================================================================== 2024-03-08T12:34:05Z INFO General Information 2024-03-08T12:34:05Z INFO ------------------- 2024-03-08T12:34:05Z INFO - Remote Host: server2.testrelm.test 2024-03-08T12:34:05Z INFO - Migration Duration: 0:01:24 2024-03-08T12:34:05Z INFO - Migration Log: /var/log/ipa-migrate.log 2024-03-08T12:34:05Z INFO - Remote Host: server2.testrelm.test 2024-03-08T12:34:05Z INFO - Remote Domain: testrelm.test 2024-03-08T12:34:05Z INFO - Local Host: server1.ipa.test 2024-03-08T12:34:05Z INFO - Local Domain: ipa.test 2024-03-08T12:34:05Z INFO - Remote Suffix: dc=testrelm,dc=test 2024-03-08T12:34:05Z INFO - Local Suffix: dc=ipa,dc=test 2024-03-08T12:34:05Z INFO - Remote Realm: TESTRELM.TEST 2024-03-08T12:34:05Z INFO - Local Realm: IPA.TEST 2024-03-08T12:34:05Z INFO Schema Migration (migrated 0/1880 definitions) 2024-03-08T12:34:05Z INFO ---------------------------------------------- 2024-03-08T12:34:05Z INFO - Attributes: 0 2024-03-08T12:34:05Z INFO - Objectclasses: 0 2024-03-08T12:34:05Z INFO DS Configuration Migration (migrated 1/134 entries) 2024-03-08T12:34:05Z INFO --------------------------------------------------- 2024-03-08T12:34:05Z INFO - DNA Plugin: 1 2024-03-08T12:34:05Z INFO Database Migration (migrated 8/479 entries) 2024-03-08T12:34:05Z INFO ------------------------------------------- 2024-03-08T12:34:05Z INFO - DNA Ranges: 2 2024-03-08T12:34:05Z INFO - Sysaccounts: 1 2024-03-08T12:34:05Z INFO - Administrator: 1 2024-03-08T12:34:05Z INFO - Groups: 3 2024-03-08T12:34:05Z INFO - AD: 1 2024-03-08T12:34:05Z INFO Action Items (4 items) 2024-03-08T12:34:05Z INFO ---------------------- 2024-03-08T12:34:05Z INFO - You will have to manually migrate IDM related configuration files. Here are some, but not all, of the configuration files to look into: - /etc/ipa/* - /etc/sssd/sssd.conf - /etc/named.conf - /etc/named/* - ... 2024-03-08T12:34:05Z INFO - The local server has been put into migration mode. Once all migration tasks are done you will have to take the server out of migration mode. 2024-03-08T12:34:05Z INFO - Administrator password is not migrated from the remote server. Reset it manually if needed. 2024-03-08T12:34:05Z INFO - SIDGEN task failed, needs investigation. 2024-03-08T12:34:05Z INFO ===============================================================================