04-15 19:20 ipadocker.cli INFO Starting /opt/pyenv/versions/3.6/bin/ipa-docker-test-runner 04-15 19:20 ipadocker.cli INFO Loading configuration 04-15 19:20 ipadocker.cli INFO Parsing configuration file .travis/ipa-test.yaml 04-15 19:20 ipadocker.config INFO Parsing YAML configuration 04-15 19:20 ipadocker.config INFO Validating retrieved configuration 04-15 19:20 ipadocker.config INFO File /home/travis/.config/ipa-docker-test-runner/config.yaml does not exist, skipping 04-15 19:20 IPAContainer INFO Creating container from dogtagpki/pki-ci:f28_106_46 04-15 19:20 IPAContainer INFO Creating container from dogtagpki/pki-ci:f28_106_46 04-15 19:20 IPAContainer INFO Pulling image dogtagpki/pki-ci:f28_106_46, this may take several minutes. 04-15 19:20 IPAContainer INFO Image pulled in successfuly. 04-15 19:20 IPAContainer INFO SUCCESS 04-15 19:20 IPAContainer INFO Starting container ID: fd952e7ce8f0cdcef5eef15041876ebb25b2afd146bacce2fc24316a6a3d16b6 04-15 19:20 ipadocker.command INFO Executing command: rm -rf /var/cache/dnf/* 04-15 19:20 ipadocker.command INFO Executing command: dnf makecache || : Copr repo for 10.6 owned by @pki 335 kB/s | 142 kB 00:00 Fedora 28 - x86_64 - Updates 1.9 kB/s | 257 B 00:00 Fedora 28 - x86_64 6.3 MB/s | 60 MB 00:09 Last metadata expiration check: 0:00:00 ago on Sun Apr 15 19:20:41 2018. Metadata cache created. 04-15 19:21 ipadocker.command INFO Executing command: dnf repolist Last metadata expiration check: 0:00:30 ago on Sun Apr 15 19:20:41 2018. repo id repo name status *fedora Fedora 28 - x86_64 57301 group_pki-10.6 Copr repo for 10.6 owned by @pki 117 *updates Fedora 28 - x86_64 - Updates 0 04-15 19:21 ipadocker.command INFO Executing command: echo "Skipping Build. Nothing to do..." Skipping Build. Nothing to do... 04-15 19:21 ipadocker.command INFO Executing command: echo "Installing recently built dogtag RPMs..." Installing recently built dogtag RPMs... 04-15 19:21 ipadocker.command INFO Executing command: find /freeipa/dogtag_rpms/ -name '*.rpm' -and -not -name '*debuginfo*' | xargs dnf install -y Last metadata expiration check: 0:00:30 ago on Sun Apr 15 19:20:41 2018. Package pki-symkey-10.6.0-1.fc28.x86_64 is already installed, skipping. Package pki-tools-10.6.0-1.fc28.x86_64 is already installed, skipping. Package python3-pki-10.6.0-1.fc28.noarch is already installed, skipping. Package pki-ca-10.6.0-1.fc28.noarch is already installed, skipping. Package pki-server-10.6.0-1.fc28.noarch is already installed, skipping. Package pki-kra-10.6.0-1.fc28.noarch is already installed, skipping. Package pki-base-10.6.0-1.fc28.noarch is already installed, skipping. Package pki-base-java-10.6.0-1.fc28.noarch is already installed, skipping. Dependencies resolved. ================================================================================ Package Arch Version Repository Size ================================================================================ Installing: pki-core-debugsource x86_64 10.6.0-1.fc28 @commandline 388 k pki-javadoc noarch 10.6.0-1.fc28 @commandline 2.3 M pki-ocsp noarch 10.6.0-1.fc28 @commandline 66 k pki-tks noarch 10.6.0-1.fc28 @commandline 78 k pki-tps x86_64 10.6.0-1.fc28 @commandline 653 k python2-pki noarch 10.6.0-1.fc28 @commandline 140 k Transaction Summary ================================================================================ Install 6 Packages Total size: 3.6 M Installed size: 61 M Downloading Packages: Running transaction check Transaction check succeeded. Running transaction test Transaction test succeeded. Running transaction Preparing : 1/1 Installing : pki-ocsp-10.6.0-1.fc28.noarch 1/6 Installing : pki-javadoc-10.6.0-1.fc28.noarch 2/6 Installing : pki-tks-10.6.0-1.fc28.noarch 3/6 Installing : python2-pki-10.6.0-1.fc28.noarch 4/6 Installing : pki-core-debugsource-10.6.0-1.fc28.x86_64 5/6 Installing : pki-tps-10.6.0-1.fc28.x86_64 6/6 Running scriptlet: pki-tps-10.6.0-1.fc28.x86_64 6/6 Verifying : pki-tps-10.6.0-1.fc28.x86_64 1/6 Verifying : pki-core-debugsource-10.6.0-1.fc28.x86_64 2/6 Verifying : python2-pki-10.6.0-1.fc28.noarch 3/6 Verifying : pki-tks-10.6.0-1.fc28.noarch 4/6 Verifying : pki-javadoc-10.6.0-1.fc28.noarch 5/6 Verifying : pki-ocsp-10.6.0-1.fc28.noarch 6/6 Installed: pki-core-debugsource.x86_64 10.6.0-1.fc28 pki-javadoc.noarch 10.6.0-1.fc28 pki-ocsp.noarch 10.6.0-1.fc28 pki-tks.noarch 10.6.0-1.fc28 pki-tps.x86_64 10.6.0-1.fc28 python2-pki.noarch 10.6.0-1.fc28 Complete! 04-15 19:21 ipadocker.command INFO Executing command: rpm -qa tomcat* pki-* freeipa-* | sort freeipa-client-4.6.90.pre1-6.1.fc28.x86_64 freeipa-client-common-4.6.90.pre1-6.1.fc28.noarch freeipa-common-4.6.90.pre1-6.1.fc28.noarch freeipa-server-4.6.90.pre1-6.1.fc28.x86_64 freeipa-server-common-4.6.90.pre1-6.1.fc28.noarch freeipa-server-dns-4.6.90.pre1-6.1.fc28.noarch freeipa-server-trust-ad-4.6.90.pre1-6.1.fc28.x86_64 pki-base-10.6.0-1.fc28.noarch pki-base-java-10.6.0-1.fc28.noarch pki-ca-10.6.0-1.fc28.noarch pki-core-debugsource-10.6.0-1.fc28.x86_64 pki-javadoc-10.6.0-1.fc28.noarch pki-kra-10.6.0-1.fc28.noarch pki-ocsp-10.6.0-1.fc28.noarch pki-server-10.6.0-1.fc28.noarch pki-symkey-10.6.0-1.fc28.x86_64 pki-tks-10.6.0-1.fc28.noarch pki-tools-10.6.0-1.fc28.x86_64 pki-tps-10.6.0-1.fc28.x86_64 tomcat-8.5.29-1.fc28.noarch tomcat-el-3.0-api-8.5.29-1.fc28.noarch tomcat-jsp-2.3-api-8.5.29-1.fc28.noarch tomcat-lib-8.5.29-1.fc28.noarch tomcat-servlet-3.1-api-8.5.29-1.fc28.noarch tomcatjss-7.3.0-1.fc28.noarch 04-15 19:21 ipadocker.command INFO Executing command: echo "Installing ipa-server..." Installing ipa-server... 04-15 19:21 ipadocker.command INFO Executing command: sysctl net.ipv6.conf.lo.disable_ipv6=0 net.ipv6.conf.lo.disable_ipv6 = 0 04-15 19:21 ipadocker.command INFO Executing command: ipa-server-install -U --domain ipa.test --realm IPA.TEST -p Secret.123 -a Secret.123 --setup-dns --setup-kra --auto-forwarders Checking DNS domain ipa.test, please wait ... The log file for this installation can be found in /var/log/ipaserver-install.log ============================================================================== This program will set up the FreeIPA Server. This includes: * Configure a stand-alone CA (dogtag) for certificate management * Configure the Network Time Daemon (ntpd) * Create and configure an instance of Directory Server * Create and configure a Kerberos Key Distribution Center (KDC) * Configure Apache (httpd) * Configure KRA (dogtag) for secret management * Configure DNS (bind) * Configure the KDC to enable PKINIT Warning: skipping DNS resolution of host master.ipa.test Checking DNS domain ipa.test., please wait ... Checking DNS forwarders, please wait ... DNS server 169.254.169.254: answer to query '. SOA' is missing DNSSEC signatures (no RRSIG data) Please fix forwarder configuration to enable DNSSEC support. (For BIND 9 add directive "dnssec-enable yes;" to "options {}") WARNING: DNSSEC validation will be disabled The IPA Master Server will be configured with: Hostname: master.ipa.test IP address(es): 172.17.0.3 Domain name: ipa.test Realm name: IPA.TEST The CA will be configured with: Subject DN: CN=Certificate Authority,O=IPA.TEST Subject base: O=IPA.TEST Chaining: self-signed BIND DNS server will be configured to serve IPA domain with: Forwarders: 169.254.169.254 Forward policy: only Reverse zone(s): No reverse zone Configuring NTP daemon (ntpd) [1/4]: stopping ntpd [2/4]: writing configuration [3/4]: configuring ntpd to start on boot [4/4]: starting ntpd Done configuring NTP daemon (ntpd). Configuring directory server (dirsrv). Estimated time: 30 seconds [1/44]: creating directory server instance [2/44]: enabling ldapi [3/44]: configure autobind for root [4/44]: stopping directory server [5/44]: updating configuration in dse.ldif [6/44]: starting directory server [7/44]: adding default schema [8/44]: enabling memberof plugin [9/44]: enabling winsync plugin [10/44]: configuring replication version plugin [11/44]: enabling IPA enrollment plugin [12/44]: configuring uniqueness plugin [13/44]: configuring uuid plugin [14/44]: configuring modrdn plugin [15/44]: configuring DNS plugin [16/44]: enabling entryUSN plugin [17/44]: configuring lockout plugin [18/44]: configuring topology plugin [19/44]: creating indices [20/44]: enabling referential integrity plugin [21/44]: configuring certmap.conf [22/44]: configure new location for managed entries [23/44]: configure dirsrv ccache [24/44]: enabling SASL mapping fallback [25/44]: restarting directory server [26/44]: adding sasl mappings to the directory [27/44]: adding default layout [28/44]: adding delegation layout [29/44]: creating container for managed entries [30/44]: configuring user private groups [31/44]: configuring netgroups from hostgroups [32/44]: creating default Sudo bind user [33/44]: creating default Auto Member layout [34/44]: adding range check plugin [35/44]: creating default HBAC rule allow_all [36/44]: adding entries for topology management [37/44]: initializing group membership [38/44]: adding master entry [39/44]: initializing domain level [40/44]: configuring Posix uid/gid generation [41/44]: adding replication acis [42/44]: activating sidgen plugin [43/44]: activating extdom plugin [44/44]: configuring directory to start on boot Done configuring directory server (dirsrv). Configuring Kerberos KDC (krb5kdc) [1/10]: adding kerberos container to the directory [2/10]: configuring KDC [3/10]: initialize kerberos container [4/10]: adding default ACIs [5/10]: creating a keytab for the directory [6/10]: creating a keytab for the machine [7/10]: adding the password extension to the directory [8/10]: creating anonymous principal [9/10]: starting the KDC [10/10]: configuring KDC to start on boot Done configuring Kerberos KDC (krb5kdc). Configuring kadmin [1/2]: starting kadmin [2/2]: configuring kadmin to start on boot Done configuring kadmin. Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes [1/28]: configuring certificate server instance [2/28]: exporting Dogtag certificate store pin [3/28]: stopping certificate server instance to update CS.cfg [4/28]: backing up CS.cfg [5/28]: disabling nonces [6/28]: set up CRL publishing [7/28]: enable PKIX certificate path discovery and validation [8/28]: starting certificate server instance [9/28]: configure certmonger for renewals [10/28]: requesting RA certificate from CA [11/28]: setting audit signing renewal to 2 years [12/28]: restarting certificate server [13/28]: publishing the CA certificate [14/28]: adding RA agent as a trusted user [15/28]: authorizing RA to modify profiles [16/28]: authorizing RA to manage lightweight CAs [17/28]: Ensure lightweight CAs container exists [18/28]: configure certificate renewals [19/28]: configure Server-Cert certificate renewal [20/28]: Configure HTTP to proxy connections [21/28]: restarting certificate server [22/28]: updating IPA configuration [23/28]: enabling CA instance [24/28]: migrating certificate profiles to LDAP [25/28]: importing IPA certificate profiles [26/28]: adding default CA ACL [27/28]: adding 'ipa' CA entry [28/28]: configuring certmonger renewal for lightweight CAs Done configuring certificate server (pki-tomcatd). Configuring directory server (dirsrv) [1/3]: configuring TLS for DS instance [2/3]: adding CA certificate entry [3/3]: restarting directory server Done configuring directory server (dirsrv). Configuring ipa-otpd [1/2]: starting ipa-otpd [2/2]: configuring ipa-otpd to start on boot Done configuring ipa-otpd. Configuring ipa-custodia [1/5]: Generating ipa-custodia config file [2/5]: Making sure custodia container exists [3/5]: Generating ipa-custodia keys [4/5]: starting ipa-custodia [5/5]: configuring ipa-custodia to start on boot Done configuring ipa-custodia. Configuring the web interface (httpd) [1/21]: stopping httpd [2/21]: backing up ssl.conf [3/21]: disabling nss.conf [4/21]: configuring mod_ssl certificate paths [5/21]: setting mod_ssl protocol list to TLSv1.0 - TLSv1.2 [6/21]: configuring mod_ssl log directory [7/21]: disabling mod_ssl OCSP [8/21]: adding URL rewriting rules [9/21]: configuring httpd [10/21]: setting up httpd keytab [11/21]: configuring Gssproxy [12/21]: setting up ssl [13/21]: configure certmonger for renewals [14/21]: publish CA cert [15/21]: clean up any existing httpd ccaches [16/21]: configuring SELinux for httpd [17/21]: create KDC proxy config [18/21]: enable KDC proxy [19/21]: starting httpd [20/21]: configuring httpd to start on boot [21/21]: enabling oddjobd Done configuring the web interface (httpd). Configuring Kerberos KDC (krb5kdc) [1/1]: installing X509 Certificate for PKINIT Done configuring Kerberos KDC (krb5kdc). Applying LDAP updates Upgrading IPA:. Estimated time: 1 minute 30 seconds [1/9]: stopping directory server [2/9]: saving configuration [3/9]: disabling listeners [4/9]: enabling DS global lock [5/9]: starting directory server [6/9]: upgrading server [7/9]: stopping directory server [8/9]: restoring configuration [9/9]: starting directory server Done. Restarting the KDC Configuring KRA server (pki-tomcatd). Estimated time: 2 minutes [1/10]: configuring KRA instance [2/10]: create KRA agent [3/10]: enabling ephemeral requests [4/10]: restarting KRA [5/10]: configure certmonger for renewals [6/10]: configure certificate renewals [7/10]: configure HTTP to proxy connections [8/10]: add vault container [9/10]: apply LDAP updates [10/10]: enabling KRA instance Done configuring KRA server (pki-tomcatd). Restarting the directory server Configuring DNS (named) [1/11]: generating rndc key file [2/11]: adding DNS container [3/11]: setting up our zone [4/11]: setting up our own record [5/11]: setting up records for other masters [6/11]: adding NS record to the zones [7/11]: setting up kerberos principal [8/11]: setting up named.conf [9/11]: setting up server configuration [10/11]: configuring named to start on boot [11/11]: changing resolv.conf to point to ourselves Done configuring DNS (named). Restarting the web server to pick up resolv.conf changes Configuring DNS key synchronization service (ipa-dnskeysyncd) [1/7]: checking status [2/7]: setting up bind-dyndb-ldap working directory [3/7]: setting up kerberos principal [4/7]: setting up SoftHSM [5/7]: adding DNSSEC containers [6/7]: creating replica keys [7/7]: configuring ipa-dnskeysyncd to start on boot Done configuring DNS key synchronization service (ipa-dnskeysyncd). Restarting ipa-dnskeysyncd Restarting named Updating DNS system records Configuring client side components Using existing certificate '/etc/ipa/ca.crt'. Client hostname: master.ipa.test Realm: IPA.TEST DNS Domain: ipa.test IPA Server: master.ipa.test BaseDN: dc=ipa,dc=test Skipping synchronizing time with NTP server. New SSSD config will be created Configured sudoers in /etc/nsswitch.conf Configured /etc/sssd/sssd.conf trying https://master.ipa.test/ipa/json [try 1]: Forwarding 'schema' to json server 'https://master.ipa.test/ipa/json' trying https://master.ipa.test/ipa/session/json [try 1]: Forwarding 'ping' to json server 'https://master.ipa.test/ipa/session/json' [try 1]: Forwarding 'ca_is_enabled' to json server 'https://master.ipa.test/ipa/session/json' Systemwide CA database updated. [try 1]: Forwarding 'host_mod' to json server 'https://master.ipa.test/ipa/session/json' SSSD enabled Configured /etc/openldap/ldap.conf Configured /etc/ssh/ssh_config /etc/ssh/sshd_config not found, skipping configuration Configuring ipa.test as NIS domain. Client configuration complete. The ipa-client-install command was successful ============================================================================== Setup complete Next steps: 1. You must make sure these network ports are open: TCP Ports: * 80, 443: HTTP/HTTPS * 389, 636: LDAP/LDAPS * 88, 464: kerberos * 53: bind UDP Ports: * 88, 464: kerberos * 53: bind * 123: ntp 2. You can now obtain a kerberos ticket using the command: 'kinit admin' This ticket will allow you to use the IPA tools (e.g., ipa user-add) and the web user interface. Be sure to back up the CA certificates stored in /root/cacert.p12 These files are required to create replicas. The password for these files is the Directory Manager password 04-15 19:29 ipadocker.command INFO Executing command: systemctl restart httpd.service 04-15 19:29 ipadocker.command INFO Executing command: echo Secret.123 | kinit admin && ipa ping Password for admin@IPA.TEST: ------------------------------------------------- IPA server version 4.6.90.pre1. API version 2.229 ------------------------------------------------- 04-15 19:29 ipadocker.command INFO Executing command: cp -r /etc/ipa/* ~/.ipa/ 04-15 19:29 ipadocker.command INFO Executing command: echo Secret.123 > ~/.ipa/.dmpw 04-15 19:29 ipadocker.command INFO Executing command: echo 'wait_for_dns=5' >> ~/.ipa/default.conf 04-15 19:29 ipadocker.command INFO Executing command: ipa-run-tests-3 --ignore test_integration --ignore test_webui --ignore test_ipapython/test_keyring.py -k-test_dns_soa --verbose test_xmlrpc/test_caacl_plugin.py test_xmlrpc/test_caacl_profile_enforcement.py test_xmlrpc/test_cert_plugin.py test_xmlrpc/test_certprofile_plugin.py test_xmlrpc/test_vault_plugin.py api.env: {'api_version': '2.229', 'basedn': ipapython.dn.DN('dc=ipa,dc=test'), 'bin': '/usr/bin', 'ca_agent_install_port': None, 'ca_agent_port': 443, 'ca_ee_install_port': None, 'ca_ee_port': 443, 'ca_host': 'master.ipa.test', 'ca_install_port': None, 'ca_port': 80, 'conf': '/root/.ipa/cli.conf', 'conf_default': '/root/.ipa/default.conf', 'confdir': '/root/.ipa', 'config_loaded': True, 'container_accounts': ipapython.dn.DN('cn=accounts'), 'container_adtrusts': ipapython.dn.DN('cn=ad,cn=trusts'), 'container_applications': ipapython.dn.DN('cn=applications,cn=configs,cn=policies'), 'container_automember': ipapython.dn.DN('cn=automember,cn=etc'), 'container_automount': ipapython.dn.DN('cn=automount'), 'container_ca': ipapython.dn.DN('cn=cas,cn=ca'), 'container_caacl': ipapython.dn.DN('cn=caacls,cn=ca'), 'container_certmap': ipapython.dn.DN('cn=certmap'), 'container_certmaprules': ipapython.dn.DN('cn=certmaprules,cn=certmap'), 'container_certprofile': ipapython.dn.DN('cn=certprofiles,cn=ca'), 'container_cifsdomains': ipapython.dn.DN('cn=ad,cn=etc'), 'container_configs': ipapython.dn.DN('cn=configs,cn=policies'), 'container_custodia': ipapython.dn.DN('cn=custodia,cn=ipa,cn=etc'), 'container_deleteuser': ipapython.dn.DN('cn=deleted users,cn=accounts,cn=provisioning'), 'container_dna': ipapython.dn.DN('cn=dna,cn=ipa,cn=etc'), 'container_dna_posix_ids': ipapython.dn.DN('cn=posix-ids,cn=dna,cn=ipa,cn=etc'), 'container_dns': ipapython.dn.DN('cn=dns'), 'container_dnsservers': ipapython.dn.DN('cn=servers,cn=dns'), 'container_group': ipapython.dn.DN('cn=groups,cn=accounts'), 'container_hbac': ipapython.dn.DN('cn=hbac'), 'container_hbacservice': ipapython.dn.DN('cn=hbacservices,cn=hbac'), 'container_hbacservicegroup': ipapython.dn.DN('cn=hbacservicegroups,cn=hbac'), 'container_host': ipapython.dn.DN('cn=computers,cn=accounts'), 'container_hostgroup': ipapython.dn.DN('cn=hostgroups,cn=accounts'), 'container_locations': ipapython.dn.DN('cn=locations,cn=etc'), 'container_masters': ipapython.dn.DN('cn=masters,cn=ipa,cn=etc'), 'container_netgroup': ipapython.dn.DN('cn=ng,cn=alt'), 'container_otp': ipapython.dn.DN('cn=otp'), 'container_permission': ipapython.dn.DN('cn=permissions,cn=pbac'), 'container_policies': ipapython.dn.DN('cn=policies'), 'container_policygroups': ipapython.dn.DN('cn=policygroups,cn=configs,cn=policies'), 'container_policylinks': ipapython.dn.DN('cn=policylinks,cn=configs,cn=policies'), 'container_privilege': ipapython.dn.DN('cn=privileges,cn=pbac'), 'container_radiusproxy': ipapython.dn.DN('cn=radiusproxy'), 'container_ranges': ipapython.dn.DN('cn=ranges,cn=etc'), 'container_realm_domains': ipapython.dn.DN('cn=Realm Domains,cn=ipa,cn=etc'), 'container_rolegroup': ipapython.dn.DN('cn=roles,cn=accounts'), 'container_roles': ipapython.dn.DN('cn=roles,cn=policies'), 'container_s4u2proxy': ipapython.dn.DN('cn=s4u2proxy,cn=etc'), 'container_selinux': ipapython.dn.DN('cn=usermap,cn=selinux'), 'container_service': ipapython.dn.DN('cn=services,cn=accounts'), 'container_stageuser': ipapython.dn.DN('cn=staged users,cn=accounts,cn=provisioning'), 'container_sudocmd': ipapython.dn.DN('cn=sudocmds,cn=sudo'), 'container_sudocmdgroup': ipapython.dn.DN('cn=sudocmdgroups,cn=sudo'), 'container_sudorule': ipapython.dn.DN('cn=sudorules,cn=sudo'), 'container_sysaccounts': ipapython.dn.DN('cn=sysaccounts,cn=etc'), 'container_topology': ipapython.dn.DN('cn=topology,cn=ipa,cn=etc'), 'container_trusts': ipapython.dn.DN('cn=trusts'), 'container_user': ipapython.dn.DN('cn=users,cn=accounts'), 'container_vault': ipapython.dn.DN('cn=vaults,cn=kra'), 'container_views': ipapython.dn.DN('cn=views,cn=accounts'), 'container_virtual': ipapython.dn.DN('cn=virtual operations,cn=etc'), 'context': 'cli', 'debug': False, 'delegate': False, 'dogtag_version': 10, 'domain': 'ipa.test', 'dot_ipa': '/root/.ipa', 'enable_ra': True, 'env_confdir': None, 'fallback': False, 'fips_mode': False, 'force_schema_check': False, 'home': '/root', 'host': 'master.ipa.test', 'http_timeout': 30, 'in_server': False, 'in_tree': True, 'interactive': True, 'ipalib': '/usr/lib/python3.6/site-packages/ipalib', 'jsonrpc_uri': 'https://master.ipa.test/ipa/json', 'kinit_lifetime': None, 'ldap_uri': 'ldapi://%2fvar%2frun%2fslapd-IPA-TEST.socket', 'log': '/root/.ipa/log/cli.log', 'logdir': '/root/.ipa/log', 'mode': 'developer', 'mount_ipa': '/ipa/', 'nss_dir': '/root/.ipa/nssdb', 'plugins_on_demand': True, 'prompt_all': False, 'ra_plugin': 'dogtag', 'realm': 'IPA.TEST', 'recommended_max_agmts': 4, 'rpc_protocol': 'jsonrpc', 'script': '/usr/bin/ipa-run-tests-3', 'server': 'master.ipa.test', 'site_packages': '/usr/lib/python3.6/site-packages', 'skip_version_check': False, 'startup_timeout': 300, 'startup_traceback': False, 'tls_ca_cert': '/root/.ipa/ca.crt', 'tls_version_max': 'tls1.2', 'tls_version_min': 'tls1.0', 'validate_api': False, 'verbose': 0, 'version': '4.6.90.pre1', 'wait_for_dns': 5, 'webui_prod': True, 'xmlrpc_uri': 'https://master.ipa.test/ipa/xml'} uname: posix.uname_result(sysname='Linux', nodename='master.ipa.test', release='4.4.0-101-generic', version='#124~14.04.1-Ubuntu SMP Fri Nov 10 19:05:36 UTC 2017', machine='x86_64') euid: 0, egid: 0 working dir: /freeipa sys.version: 3.6.5 (default, Mar 29 2018, 18:20:46) [GCC 8.0.1 20180317 (Red Hat 8.0.1-0.19)] ============================= test session starts ============================== platform linux -- Python 3.6.5, pytest-3.4.2, py-1.5.3, pluggy-0.6.0 -- /usr/bin/python3 cachedir: .pytest_cache rootdir: /freeipa, inifile: tox.ini plugins: sourceorder-0.5, multihost-3.0 collecting ... collected 196 items test_caacl_plugin.py::TestDefaultACL::test_default_acl_present <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 0%] test_caacl_plugin.py::TestCAACLbasicCRUD::test_create <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 1%] test_caacl_plugin.py::TestCAACLbasicCRUD::test_delete <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 1%] test_caacl_plugin.py::TestCAACLbasicCRUD::test_disable <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 2%] test_caacl_plugin.py::TestCAACLbasicCRUD::test_disable_twice <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 2%] test_caacl_plugin.py::TestCAACLbasicCRUD::test_enable <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 3%] test_caacl_plugin.py::TestCAACLbasicCRUD::test_enable_twice <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 3%] test_caacl_plugin.py::TestCAACLbasicCRUD::test_find <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 4%] test_caacl_plugin.py::TestCAACLMembers::test_category_member_exclusivity <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 4%] test_caacl_plugin.py::TestCAACLMembers::test_mod_delete_category <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 5%] test_caacl_plugin.py::TestCAACLMembers::test_add_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 5%] test_caacl_plugin.py::TestCAACLMembers::test_remove_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 6%] test_caacl_plugin.py::TestCAACLMembers::test_add_ca <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 6%] test_caacl_plugin.py::TestCAACLMembers::test_remove_ca <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 7%] test_caacl_plugin.py::TestCAACLMembers::test_add_invalid_value_service <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 7%] test_caacl_plugin.py::TestCAACLMembers::test_add_invalid_value_user <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 8%] test_caacl_plugin.py::TestCAACLMembers::test_add_invalid_value_host <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 8%] test_caacl_plugin.py::TestCAACLMembers::test_add_invalid_value_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 9%] test_caacl_plugin.py::TestCAACLMembers::test_add_invalid_value_ca <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 9%] test_caacl_plugin.py::TestCAACLMembers::test_add_staged_user_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_plugin.py PASSED [ 10%] test_caacl_profile_enforcement.py::TestCertSignMIME::test_cert_import <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 10%] test_caacl_profile_enforcement.py::TestCertSignMIME::test_create_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 11%] test_caacl_profile_enforcement.py::TestCertSignMIME::test_add_profile_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 11%] test_caacl_profile_enforcement.py::TestCertSignMIME::test_add_user_to_group <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 12%] test_caacl_profile_enforcement.py::TestCertSignMIME::test_add_group_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 12%] test_caacl_profile_enforcement.py::TestCertSignMIME::test_sign_smime_csr <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 13%] test_caacl_profile_enforcement.py::TestCertSignMIME::test_sign_smime_csr_full_principal <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 13%] test_caacl_profile_enforcement.py::TestSignWithDisabledACL::test_import_profile_and_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 14%] test_caacl_profile_enforcement.py::TestSignWithDisabledACL::test_add_profile_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 14%] test_caacl_profile_enforcement.py::TestSignWithDisabledACL::test_add_user_to_group <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 15%] test_caacl_profile_enforcement.py::TestSignWithDisabledACL::test_add_group_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 15%] test_caacl_profile_enforcement.py::TestSignWithDisabledACL::test_disable_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 16%] test_caacl_profile_enforcement.py::TestSignWithDisabledACL::test_signing_with_disabled_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 16%] test_caacl_profile_enforcement.py::TestSignWithDisabledACL::test_admin_overrides_disabled_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 17%] test_caacl_profile_enforcement.py::TestSignWithoutGroupMembership::test_import_profile_and_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 17%] test_caacl_profile_enforcement.py::TestSignWithoutGroupMembership::test_add_profile_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 18%] test_caacl_profile_enforcement.py::TestSignWithoutGroupMembership::test_add_group_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 18%] test_caacl_profile_enforcement.py::TestSignWithoutGroupMembership::test_signing_with_non_member_principal <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 19%] test_caacl_profile_enforcement.py::TestSignWithoutGroupMembership::test_admin_overrides_group_membership <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 19%] test_caacl_profile_enforcement.py::TestSignWithChangedProfile::test_prepare_env <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 20%] test_caacl_profile_enforcement.py::TestSignWithChangedProfile::test_prepare_user_and_group <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 20%] test_caacl_profile_enforcement.py::TestSignWithChangedProfile::test_modify_smime_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 21%] test_caacl_profile_enforcement.py::TestSignWithChangedProfile::test_sign_smime_csr <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 21%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_cert_import <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 22%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_create_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 22%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_create_subca <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 23%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_add_profile_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 23%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_add_subca_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 24%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_add_user_to_group <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 25%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_add_group_to_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 25%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_sign_smime_csr <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 26%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_sign_smime_csr_full_principal <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 26%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_verify_cert_issuer_dn_is_subca <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 27%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_sign_smime_csr_fallback_to_default_CA <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 27%] test_caacl_profile_enforcement.py::TestCertSignMIMEwithSubCA::test_sign_smime_csr_fallback_to_default_cert_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 28%] test_caacl_profile_enforcement.py::TestNoMatchForSubjectAltNameDnsName::test_prepare_caacl_hosts <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 28%] test_caacl_profile_enforcement.py::TestNoMatchForSubjectAltNameDnsName::test_prepare_caacl_CA <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 29%] test_caacl_profile_enforcement.py::TestNoMatchForSubjectAltNameDnsName::test_prepare_caacl_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 29%] test_caacl_profile_enforcement.py::TestNoMatchForSubjectAltNameDnsName::test_prepare_caacl_services <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 30%] test_caacl_profile_enforcement.py::TestNoMatchForSubjectAltNameDnsName::test_request_cert_with_not_allowed_SAN <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 30%] test_caacl_profile_enforcement.py::TestPrincipalAliasForSubjectAltNameDnsName::test_prepare_caacl_hosts <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 31%] test_caacl_profile_enforcement.py::TestPrincipalAliasForSubjectAltNameDnsName::test_prepare_caacl_CA <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 31%] test_caacl_profile_enforcement.py::TestPrincipalAliasForSubjectAltNameDnsName::test_prepare_caacl_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 32%] test_caacl_profile_enforcement.py::TestPrincipalAliasForSubjectAltNameDnsName::test_prepare_caacl_services <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 32%] test_caacl_profile_enforcement.py::TestPrincipalAliasForSubjectAltNameDnsName::test_add_principal_alias <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 33%] test_caacl_profile_enforcement.py::TestPrincipalAliasForSubjectAltNameDnsName::test_request_cert_with_SAN_matching_principal_alias <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 33%] test_caacl_profile_enforcement.py::TestSignCertificateWithInvalidSAN::test_prepare_caacl_hosts <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 34%] test_caacl_profile_enforcement.py::TestSignCertificateWithInvalidSAN::test_prepare_caacl_CA <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 34%] test_caacl_profile_enforcement.py::TestSignCertificateWithInvalidSAN::test_prepare_caacl_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 35%] test_caacl_profile_enforcement.py::TestSignCertificateWithInvalidSAN::test_prepare_caacl_services <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 35%] test_caacl_profile_enforcement.py::TestSignCertificateWithInvalidSAN::test_prepare_add_host_2 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 36%] test_caacl_profile_enforcement.py::TestSignCertificateWithInvalidSAN::test_request_cert_with_not_allowed_SAN <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 36%] test_caacl_profile_enforcement.py::TestSignServiceCertManagedByMultipleHosts::test_prepare_caacl_hosts <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 37%] test_caacl_profile_enforcement.py::TestSignServiceCertManagedByMultipleHosts::test_prepare_caacl_CA <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 37%] test_caacl_profile_enforcement.py::TestSignServiceCertManagedByMultipleHosts::test_prepare_caacl_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 38%] test_caacl_profile_enforcement.py::TestSignServiceCertManagedByMultipleHosts::test_prepare_caacl_services <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 38%] test_caacl_profile_enforcement.py::TestSignServiceCertManagedByMultipleHosts::test_prepare_add_host_2 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 39%] test_caacl_profile_enforcement.py::TestSignServiceCertManagedByMultipleHosts::test_make_service_managed_by_each_host <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 39%] test_caacl_profile_enforcement.py::TestSignServiceCertManagedByMultipleHosts::test_extend_the_ca_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 40%] test_caacl_profile_enforcement.py::TestSignServiceCertManagedByMultipleHosts::test_request_cert_with_additional_host <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 40%] test_caacl_profile_enforcement.py::TestSignServiceCertWithoutSANServiceInACL::test_prepare_caacl_hosts <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 41%] test_caacl_profile_enforcement.py::TestSignServiceCertWithoutSANServiceInACL::test_prepare_caacl_CA <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 41%] test_caacl_profile_enforcement.py::TestSignServiceCertWithoutSANServiceInACL::test_prepare_caacl_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 42%] test_caacl_profile_enforcement.py::TestSignServiceCertWithoutSANServiceInACL::test_prepare_caacl_services <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 42%] test_caacl_profile_enforcement.py::TestSignServiceCertWithoutSANServiceInACL::test_prepare_add_host_2 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 43%] test_caacl_profile_enforcement.py::TestSignServiceCertWithoutSANServiceInACL::test_make_service_managed_by_each_host <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 43%] test_caacl_profile_enforcement.py::TestSignServiceCertWithoutSANServiceInACL::test_extend_the_ca_acl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 44%] test_caacl_profile_enforcement.py::TestSignServiceCertWithoutSANServiceInACL::test_request_cert_with_additional_host <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 44%] test_caacl_profile_enforcement.py::TestManagedByACIOnCertRequest::test_prepare_caacl_hosts <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 45%] test_caacl_profile_enforcement.py::TestManagedByACIOnCertRequest::test_prepare_caacl_CA <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 45%] test_caacl_profile_enforcement.py::TestManagedByACIOnCertRequest::test_prepare_caacl_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 46%] test_caacl_profile_enforcement.py::TestManagedByACIOnCertRequest::test_prepare_caacl_services <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 46%] test_caacl_profile_enforcement.py::TestManagedByACIOnCertRequest::test_prepare_add_host_2 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 47%] test_caacl_profile_enforcement.py::TestManagedByACIOnCertRequest::test_update_the_caacl <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 47%] test_caacl_profile_enforcement.py::TestManagedByACIOnCertRequest::test_issuing_service_cert_by_unrelated_host <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py PASSED [ 48%] test_caacl_profile_enforcement.py::TestManagedByACIOnCertRequest::test_issuing_service_cert_by_related_host <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py FAILED [ 48%] test_cert_plugin.py::test_cert::test_0001_cert_add <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 49%] test_cert_plugin.py::test_cert::test_0002_cert_add <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 50%] test_cert_plugin.py::test_cert::test_0003_service_show <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 50%] test_cert_plugin.py::test_cert::test_0004_service_find <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 51%] test_cert_plugin.py::test_cert::test_0005_cert_uris <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 51%] test_cert_plugin.py::test_cert::test_0006_cert_renew <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 52%] test_cert_plugin.py::test_cert::test_0007_service_show <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 52%] test_cert_plugin.py::test_cert::test_0008_cert_show <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 53%] test_cert_plugin.py::test_cert::test_0009_cert_find <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 53%] test_cert_plugin.py::test_cert::test_00010_san_in_cert <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 54%] test_cert_plugin.py::test_cert::test_00011_emails_are_valid <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 54%] test_cert_plugin.py::test_cert::test_99999_cleanup <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 55%] test_cert_plugin.py::test_cert_find::test_0001_find_all <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 55%] test_cert_plugin.py::test_cert_find::test_0002_find_CA <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 56%] test_cert_plugin.py::test_cert_find::test_0003_find_OCSP <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 56%] test_cert_plugin.py::test_cert_find::test_0004_find_this_host <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 57%] test_cert_plugin.py::test_cert_find::test_0005_find_this_host_exact <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 57%] test_cert_plugin.py::test_cert_find::test_0006_find_this_short_host_exact <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 58%] test_cert_plugin.py::test_cert_find::test_0017_find_by_issuedon <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 58%] test_cert_plugin.py::test_cert_find::test_0018_find_through_issuedon <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 59%] test_cert_plugin.py::test_cert_find::test_0019_find_notvalid_before <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 59%] test_cert_plugin.py::test_cert_find::test_0020_find_notvalid_before <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 60%] test_cert_plugin.py::test_cert_find::test_0021_find_notvalid_before <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 60%] test_cert_plugin.py::test_cert_find::test_0022_find_notvalid_before <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 61%] test_cert_plugin.py::test_cert_find::test_0023_find_notvalid_after <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 61%] test_cert_plugin.py::test_cert_find::test_0024_find_notvalid_after <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 62%] test_cert_plugin.py::test_cert_find::test_0025_find_notvalid_after <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 62%] test_cert_plugin.py::test_cert_find::test_0026_find_notvalid_after <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 63%] test_cert_plugin.py::test_cert_find::test_0027_sizelimit_zero <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 63%] test_cert_plugin.py::test_cert_find::test_0028_find_negative_size <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 64%] test_cert_plugin.py::test_cert_find::test_0029_search_for_notfound <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 64%] test_cert_plugin.py::test_cert_find::test_0030_search_for_testcerts <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 65%] test_cert_plugin.py::test_cert_find::test_0031_search_on_invalid_date <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 65%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_0 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 66%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_1 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 66%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_2 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 67%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_3 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 67%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_4 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 68%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_5 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 68%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_6 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 69%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_8 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 69%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_9 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 70%] test_cert_plugin.py::test_cert_revocation::test_revoke_with_reason_10 <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_cert_plugin.py PASSED [ 70%] test_certprofile_plugin.py::TestDefaultProfile::test_default_profile_present <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 71%] test_certprofile_plugin.py::TestDefaultProfile::test_deleting_default_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 71%] test_certprofile_plugin.py::TestDefaultProfile::test_try_rename_by_setattr <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 72%] test_certprofile_plugin.py::TestDefaultProfile::test_try_rename_by_rename_option <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 72%] test_certprofile_plugin.py::TestProfileCRUD::test_create_duplicate <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 73%] test_certprofile_plugin.py::TestProfileCRUD::test_retrieve_simple <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 73%] test_certprofile_plugin.py::TestProfileCRUD::test_retrieve_all <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 74%] test_certprofile_plugin.py::TestProfileCRUD::test_export_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 75%] test_certprofile_plugin.py::TestProfileCRUD::test_search_simple <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 75%] test_certprofile_plugin.py::TestProfileCRUD::test_search_all <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 76%] test_certprofile_plugin.py::TestProfileCRUD::test_update_store <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 76%] test_certprofile_plugin.py::TestProfileCRUD::test_update_description <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 77%] test_certprofile_plugin.py::TestProfileCRUD::test_update_by_malformed_profile <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 77%] test_certprofile_plugin.py::TestProfileCRUD::test_try_rename_by_setattr <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 78%] test_certprofile_plugin.py::TestProfileCRUD::test_delete <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 78%] test_certprofile_plugin.py::TestProfileCRUD::test_try_rename_by_rename_option <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 79%] test_certprofile_plugin.py::TestMalformedProfile::test_malformed_import <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 79%] test_certprofile_plugin.py::TestImportFromXML::test_import_xml <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_certprofile_plugin.py PASSED [ 80%] test_vault_plugin.py::test_vault_plugin::test_command[0000: vault_add: Create private vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 80%] test_vault_plugin.py::test_vault_plugin::test_command[0001: vault_find: Find private vaults] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 81%] test_vault_plugin.py::test_vault_plugin::test_command[0002: vault_show: Show private vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 81%] test_vault_plugin.py::test_vault_plugin::test_command[0003: vault_mod: Modify private vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 82%] test_vault_plugin.py::test_vault_plugin::test_command[0004: vault_del: Delete private vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 82%] test_vault_plugin.py::test_vault_plugin::test_command[0005: vault_add: Create service vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 83%] test_vault_plugin.py::test_vault_plugin::test_command[0006: vault_find: Find service vaults] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 83%] test_vault_plugin.py::test_vault_plugin::test_command[0007: vault_show: Show service vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 84%] test_vault_plugin.py::test_vault_plugin::test_command[0008: vault_mod: Modify service vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 84%] test_vault_plugin.py::test_vault_plugin::test_command[0009: vault_del: Delete service vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 85%] test_vault_plugin.py::test_vault_plugin::test_command[0010: vault_add: Create shared vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 85%] test_vault_plugin.py::test_vault_plugin::test_command[0011: vault_find: Find shared vaults] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 86%] test_vault_plugin.py::test_vault_plugin::test_command[0012: vault_show: Show shared vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 86%] test_vault_plugin.py::test_vault_plugin::test_command[0013: vault_mod: Modify shared vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 87%] test_vault_plugin.py::test_vault_plugin::test_command[0014: vault_del: Delete shared vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 87%] test_vault_plugin.py::test_vault_plugin::test_command[0015: vault_add: Create user vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 88%] test_vault_plugin.py::test_vault_plugin::test_command[0016: vault_find: Find user vaults] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 88%] test_vault_plugin.py::test_vault_plugin::test_command[0017: vault_show: Show user vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 89%] test_vault_plugin.py::test_vault_plugin::test_command[0018: vault_mod: Modify user vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 89%] test_vault_plugin.py::test_vault_plugin::test_command[0019: vault_del: Delete user vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 90%] test_vault_plugin.py::test_vault_plugin::test_command[0020: vault_add: Create standard vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 90%] test_vault_plugin.py::test_vault_plugin::test_command[0021: vault_archive: Archive secret into standard vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 91%] test_vault_plugin.py::test_vault_plugin::test_command[0022: vault_retrieve: Retrieve secret from standard vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 91%] test_vault_plugin.py::test_vault_plugin::test_command[0023: vault_mod: Change standard vault to symmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 92%] test_vault_plugin.py::test_vault_plugin::test_command[0024: vault_retrieve: Retrieve secret from standard vault converted to symmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 92%] test_vault_plugin.py::test_vault_plugin::test_command[0025: vault_add: Create symmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 93%] test_vault_plugin.py::test_vault_plugin::test_command[0026: vault_archive: Archive secret into symmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 93%] test_vault_plugin.py::test_vault_plugin::test_command[0027: vault_retrieve: Retrieve secret from symmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 94%] test_vault_plugin.py::test_vault_plugin::test_command[0028: vault_mod: Change symmetric vault password] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 94%] test_vault_plugin.py::test_vault_plugin::test_command[0029: vault_retrieve: Retrieve secret from symmetric vault with new password] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 95%] test_vault_plugin.py::test_vault_plugin::test_command[0030: vault_mod: Change symmetric vault to asymmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 95%] test_vault_plugin.py::test_vault_plugin::test_command[0031: vault_retrieve: Retrieve secret from symmetric vault converted to asymmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 96%] test_vault_plugin.py::test_vault_plugin::test_command[0032: vault_add: Create asymmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 96%] test_vault_plugin.py::test_vault_plugin::test_command[0033: vault_archive: Archive secret into asymmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 97%] test_vault_plugin.py::test_vault_plugin::test_command[0034: vault_retrieve: Retrieve secret from asymmetric vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 97%] test_vault_plugin.py::test_vault_plugin::test_command[0035: vault_mod: Change asymmetric vault keys] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 98%] test_vault_plugin.py::test_vault_plugin::test_command[0036: vault_retrieve: Retrieve secret from asymmetric vault with new keys] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 98%] test_vault_plugin.py::test_vault_plugin::test_command[0037: vault_mod: Change asymmetric vault to standard vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [ 99%] test_vault_plugin.py::test_vault_plugin::test_command[0038: vault_retrieve: Retrieve secret from asymmetric vault converted to standard vault] <- ../usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/xmlrpc_test.py PASSED [100%] =================================== FAILURES =================================== _____________________ TestCertSignMIME.test_sign_smime_csr _____________________ self = smime_profile = smime_user = 'alice' def test_sign_smime_csr(self, smime_profile, smime_user): csr = generate_user_csr(smime_user) with change_principal(smime_user, SMIME_USER_PW): api.Command.cert_request(csr, principal=smime_user, > profile_id=smime_profile.name) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:135: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIICgTCCAWkCAQAwEDEOMAwGA1UEAwwFYWxpY2UwggEiMA0GCSqGSIb3DQEBAQUA\nA4IBDwAwggEK...ST-----\n',), {'principal': ipapython.kerberos.Principal('alice@IPA.TEST'), 'profile_id': 'smime', 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'alice@IPA.TEST' is not permitted to use CA 'ipa' with profile 'smime' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ------------------------------ Captured log call ------------------------------- rpc.py 1056 INFO trying https://master.ipa.test/ipa/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json _____________ TestCertSignMIME.test_sign_smime_csr_full_principal ______________ self = smime_profile = smime_user = 'alice' def test_sign_smime_csr_full_principal(self, smime_profile, smime_user): csr = generate_user_csr(smime_user) smime_user_principal = '@'.join((smime_user, api.env.realm)) with change_principal(smime_user, SMIME_USER_PW): api.Command.cert_request(csr, principal=smime_user_principal, > profile_id=smime_profile.name) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:142: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIICgTCCAWkCAQAwEDEOMAwGA1UEAwwFYWxpY2UwggEiMA0GCSqGSIb3DQEBAQUA\nA4IBDwAwggEK...ST-----\n',), {'principal': ipapython.kerberos.Principal('alice@IPA.TEST'), 'profile_id': 'smime', 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'alice@IPA.TEST' is not permitted to use CA 'ipa' with profile 'smime' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ------------------------------ Captured log call ------------------------------- rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json --------------------------- Captured stdout teardown --------------------------- Ran command: ipaserver.plugins.certprofile.certprofile_del()('smime', version='2.229'): OK Ran command: ipaserver.plugins.caacl.caacl_del()('smime_acl', version='2.229'): OK ---------------------------- Captured log teardown ----------------------------- rpc.py 1147 INFO [try 1]: Forwarding 'user_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'certprofile_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'caacl_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'group_del/1' to json server 'https://master.ipa.test/ipa/session/json' ________________ TestSignWithChangedProfile.test_sign_smime_csr ________________ self = smime_profile = smime_user = 'alice' def test_sign_smime_csr(self, smime_profile, smime_user): csr = generate_user_csr(smime_user) with change_principal(smime_user, SMIME_USER_PW): with pytest.raises(errors.CertificateOperationError): api.Command.cert_request(csr, principal=smime_user, > profile_id=smime_profile.name) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:256: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py :62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIICgTCCAWkCAQAwEDEOMAwGA1UEAwwFYWxpY2UwggEiMA0GCSqGSIb3DQEBAQUA\nA4IBDwAwggEK...ST-----\n',), {'principal': ipapython.kerberos.Principal('alice@IPA.TEST'), 'profile_id': 'smime', 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'alice@IPA.TEST' is not permitted to use CA 'ipa' with profile 'smime' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ------------------------------ Captured log call ------------------------------- rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json --------------------------- Captured stdout teardown --------------------------- Ran command: ipaserver.plugins.certprofile.certprofile_del()('smime', version='2.229'): OK Ran command: ipaserver.plugins.caacl.caacl_del()('smime_acl', version='2.229'): OK ---------------------------- Captured log teardown ----------------------------- rpc.py 1147 INFO [try 1]: Forwarding 'user_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'certprofile_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'caacl_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'group_del/1' to json server 'https://master.ipa.test/ipa/session/json' ________________ TestCertSignMIMEwithSubCA.test_sign_smime_csr _________________ self = smime_profile = smime_user = 'alice' smime_signing_ca = def test_sign_smime_csr(self, smime_profile, smime_user, smime_signing_ca): csr = generate_user_csr(smime_user) with change_principal(smime_user, SMIME_USER_PW): api.Command.cert_request(csr, principal=smime_user, profile_id=smime_profile.name, > cacn=smime_signing_ca.name) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:312: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIICgTCCAWkCAQAwEDEOMAwGA1UEAwwFYWxpY2UwggEiMA0GCSqGSIb3DQEBAQUA\nA4IBDwAwggEK...e-signing-ca', 'principal': ipapython.kerberos.Principal('alice@IPA.TEST'), 'profile_id': 'smime', 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'alice@IPA.TEST' is not permitted to use CA 'smime-signing-ca' with profile 'smime' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ------------------------------ Captured log call ------------------------------- rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json _________ TestCertSignMIMEwithSubCA.test_sign_smime_csr_full_principal _________ self = smime_profile = smime_user = 'alice' smime_signing_ca = def test_sign_smime_csr_full_principal( self, smime_profile, smime_user, smime_signing_ca): csr = generate_user_csr(smime_user) smime_user_principal = '@'.join((smime_user, api.env.realm)) with change_principal(smime_user, SMIME_USER_PW): api.Command.cert_request(csr, principal=smime_user_principal, profile_id=smime_profile.name, > cacn=smime_signing_ca.name) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:321: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py :824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIICgTCCAWkCAQAwEDEOMAwGA1UEAwwFYWxpY2UwggEiMA0GCSqGSIb3DQEBAQUA\nA4IBDwAwggEK...e-signing-ca', 'principal': ipapython.kerberos.Principal('alice@IPA.TEST'), 'profile_id': 'smime', 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'alice@IPA.TEST' is not permitted to use CA 'smime-signing-ca' with profile 'smime' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ------------------------------ Captured log call ------------------------------- rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json ________ TestCertSignMIMEwithSubCA.test_verify_cert_issuer_dn_is_subca _________ self = smime_profile = smime_user = 'alice' smime_signing_ca = def test_verify_cert_issuer_dn_is_subca( self, smime_profile, smime_user, smime_signing_ca): csr = generate_user_csr(smime_user) smime_user_principal = '@'.join((smime_user, api.env.realm)) with change_principal(smime_user, SMIME_USER_PW): cert_info = api.Command.cert_request( csr, principal=smime_user_principal, > profile_id=smime_profile.name, cacn=smime_signing_ca.name) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:330: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py :1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIICgTCCAWkCAQAwEDEOMAwGA1UEAwwFYWxpY2UwggEiMA0GCSqGSIb3DQEBAQUA\nA4IBDwAwggEK...e-signing-ca', 'principal': ipapython.kerberos.Principal('alice@IPA.TEST'), 'profile_id': 'smime', 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'alice@IPA.TEST' is not permitted to use CA 'smime-signing-ca' with profile 'smime' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ------------------------------ Captured log call ------------------------------- rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json __ TestNoMatchForSubjectAltNameDnsName.test_request_cert_with_not_allowed_SAN __ self = santest_subca = santest_host_1 = santest_service_host_1 = santest_csr = '-----BEGIN CERTIFICATE REQUEST-----\nMIIC4zCCAcsCAQAwNTEgMB4GA1UEAwwXc2FudGVzdC1ob3N0LTEuaXBhLnRlc3Qx\nETAPBgNVBAoMCE...FU2x2iUeiLBniXaxjgwJBcFwKBtujAzn6lLgXVm/PYV/ImJ\noweqN7oFBdUb+94W+b2wtmQRc+BAiVQ=\n-----END CERTIFICATE REQUEST-----\n' def test_request_cert_with_not_allowed_SAN( self, santest_subca, santest_host_1, santest_service_host_1, santest_csr): with host_keytab(santest_host_1.name) as keytab_filename: with change_principal(santest_host_1.attrs['krbcanonicalname'][0], keytab=keytab_filename): with pytest.raises(errors.NotFound): api.Command.cert_request( santest_csr, principal=santest_service_host_1.name, > cacn=santest_subca.name ) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:525: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIIC4zCCAcsCAQAwNTEgMB4GA1UEAwwXc2FudGVzdC1ob3N0LTEuaXBhLnRlc3Qx\nETAPBgNVBAoM...profile-subca', 'principal': ipapython.kerberos.Principal('srv/santest-host-1.ipa.test@IPA.TEST'), 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'srv/santest-host-1.ipa.test@IPA.TEST' is not permitted to use CA 'default-profile-subca' with profile 'caIPAserviceCert' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ---------------------------- Captured stdout setup ----------------------------- Ran command: ipaserver.plugins.host.host_del()('santest-host-2.ipa.test', version='2.229'): NotFound: santest-host-2.ipa.test: host not found ------------------------------ Captured log setup ------------------------------ rpc.py 1147 INFO [try 1]: Forwarding 'host_del/1' to json server 'https://master.ipa.test/ipa/session/json' ------------------------------ Captured log call ------------------------------- rpc.py 1056 INFO trying https://master.ipa.test/ipa/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json --------------------------- Captured stdout teardown --------------------------- Ran command: ipaserver.plugins.host.host_del()('santest-host-2.ipa.test', version='2.229'): NotFound: santest-host-2.ipa.test: host not found Ran command: ipaserver.plugins.service.service_del()('srv/santest-host-1.ipa.test@IPA.TEST', version='2.229'): OK Ran command: ipaserver.plugins.host.host_del()('santest-host-1.ipa.test', version='2.229'): OK Ran command: ipaserver.plugins.ca.ca_del()('default-profile-subca', version='2.229'): OK Ran command: ipaserver.plugins.caacl.caacl_del()('default_profile_subca', version='2.229'): OK ---------------------------- Captured log teardown ----------------------------- rpc.py 1147 INFO [try 1]: Forwarding 'host_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'service_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'host_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'ca_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'caacl_del/1' to json server 'https://master.ipa.test/ipa/session/json' TestPrincipalAliasForSubjectAltNameDnsName.test_request_cert_with_SAN_matching_principal_alias self = santest_subca = santest_host_1 = santest_service_host_1 = santest_csr = '-----BEGIN CERTIFICATE REQUEST-----\nMIIC4zCCAcsCAQAwNTEgMB4GA1UEAwwXc2FudGVzdC1ob3N0LTEuaXBhLnRlc3Qx\nETAPBgNVBAoMCE...iW7ZXYJvNfuGINP6V0ItnIR4Il8uPgsJfCCl6jZvMXVPBpt\n1yi6GiSUFlfaD9ul+CBAbOiRrITor8c=\n-----END CERTIFICATE REQUEST-----\n' def test_request_cert_with_SAN_matching_principal_alias( self, santest_subca, santest_host_1, santest_service_host_1, santest_csr): with host_keytab(santest_host_1.name) as keytab_filename: with change_principal( santest_host_1.attrs['krbcanonicalname'][0], keytab=keytab_filename): api.Command.cert_request( santest_csr, principal=santest_service_host_1.name, > cacn=santest_subca.name ) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:552: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py :1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIIC4zCCAcsCAQAwNTEgMB4GA1UEAwwXc2FudGVzdC1ob3N0LTEuaXBhLnRlc3Qx\nETAPBgNVBAoM...profile-subca', 'principal': ipapython.kerberos.Principal('srv/santest-host-1.ipa.test@IPA.TEST'), 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'srv/santest-host-1.ipa.test@IPA.TEST' is not permitted to use CA 'default-profile-subca' with profile 'caIPAserviceCert' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ------------------------------ Captured log call ------------------------------- rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json --------------------------- Captured stdout teardown --------------------------- Ran command: ipaserver.plugins.service.service_del()('srv/santest-host-2.ipa.test@IPA.TEST', version='2.229'): NotFound: srv/santest-host-2.ipa.test@IPA.TEST: service not found Ran command: ipaserver.plugins.host.host_del()('santest-host-2.ipa.test', version='2.229'): NotFound: santest-host-2.ipa.test: host not found Ran command: ipaserver.plugins.service.service_del()('srv/santest-host-1.ipa.test@IPA.TEST', version='2.229'): OK Ran command: ipaserver.plugins.host.host_del()('santest-host-1.ipa.test', version='2.229'): OK Ran command: ipaserver.plugins.ca.ca_del()('default-profile-subca', version='2.229'): OK Ran command: ipaserver.plugins.caacl.caacl_del()('default_profile_subca', version='2.229'): OK ---------------------------- Captured log teardown ----------------------------- rpc.py 1147 INFO [try 1]: Forwarding 'service_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'host_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'service_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'host_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'ca_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'caacl_del/1' to json server 'https://master.ipa.test/ipa/session/json' TestSignServiceCertManagedByMultipleHosts.test_request_cert_with_additional_host self = santest_subca = santest_host_1 = santest_host_2 = santest_service_host_1 = santest_csr = '-----BEGIN CERTIFICATE REQUEST-----\nMIIC4zCCAcsCAQAwNTEgMB4GA1UEAwwXc2FudGVzdC1ob3N0LTEuaXBhLnRlc3Qx\nETAPBgNVBAoMCE...jYlk+rHk270kXg06Cvm7MDRUQjCttG04SRL3fNT1Hy/t9Zy\nAStEC6sW3mh6Q88YyBPGFhM/nvHfHT4=\n-----END CERTIFICATE REQUEST-----\n' def test_request_cert_with_additional_host( self, santest_subca, santest_host_1, santest_host_2, santest_service_host_1, santest_csr): with host_keytab(santest_host_1.name) as keytab_filename: with change_principal(santest_host_1.attrs['krbcanonicalname'][0], keytab=keytab_filename): api.Command.cert_request( santest_csr, principal=santest_service_host_1.name, > cacn=santest_subca.name ) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:615: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py :1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIIC4zCCAcsCAQAwNTEgMB4GA1UEAwwXc2FudGVzdC1ob3N0LTEuaXBhLnRlc3Qx\nETAPBgNVBAoM...profile-subca', 'principal': ipapython.kerberos.Principal('srv/santest-host-1.ipa.test@IPA.TEST'), 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'srv/santest-host-1.ipa.test@IPA.TEST' is not permitted to use CA 'default-profile-subca' with profile 'caIPAserviceCert' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ------------------------------ Captured log call ------------------------------- rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json --------------------------- Captured stdout teardown --------------------------- Ran command: ipaserver.plugins.service.service_del()('srv/santest-host-1.ipa.test@IPA.TEST', version='2.229'): OK Ran command: ipaserver.plugins.service.service_del()('srv/santest-host-2.ipa.test@IPA.TEST', version='2.229'): OK Ran command: ipaserver.plugins.host.host_del()('santest-host-2.ipa.test', version='2.229'): OK Ran command: ipaserver.plugins.host.host_del()('santest-host-1.ipa.test', version='2.229'): OK Ran command: ipaserver.plugins.ca.ca_del()('default-profile-subca', version='2.229'): OK Ran command: ipaserver.plugins.caacl.caacl_del()('default_profile_subca', version='2.229'): OK ---------------------------- Captured log teardown ----------------------------- rpc.py 1147 INFO [try 1]: Forwarding 'service_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'service_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'host_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'host_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'ca_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'caacl_del/1' to json server 'https://master.ipa.test/ipa/session/json' ___ TestManagedByACIOnCertRequest.test_issuing_service_cert_by_related_host ____ self = santest_subca = santest_host_1 = santest_host_2 = santest_service_host_1 = santest_csr = '-----BEGIN CERTIFICATE REQUEST-----\nMIIC4zCCAcsCAQAwNTEgMB4GA1UEAwwXc2FudGVzdC1ob3N0LTEuaXBhLnRlc3Qx\nETAPBgNVBAoMCE...AegcI1dQSGfJjFUYLNmkpHekMcIAcGbpLPrbWOxJQCyND41\nL1VVAvq1SMIbGYyLjNV1jGijut1QjOM=\n-----END CERTIFICATE REQUEST-----\n' def test_issuing_service_cert_by_related_host(self, santest_subca, santest_host_1, santest_host_2, santest_service_host_1, santest_csr): # The test case alters the previous state by making # the service managed by the second host. # Then it attempts to request the certificate again api.Command['service_add_host']( santest_service_host_1.name, host=[santest_host_2.fqdn] ) with host_keytab(santest_host_2.name) as keytab_filename: with change_principal(santest_host_2.attrs['krbcanonicalname'][0], keytab=keytab_filename): api.Command.cert_request( santest_csr, principal=santest_service_host_1.name, > cacn=santest_subca.name ) /usr/lib/python3.6/site-packages/ipatests/test_xmlrpc/test_caacl_profile_enforcement.py:716: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ /usr/lib/python3.6/site-packages/ipalib/frontend.py:450: in __call__ return self.__do_call(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:478: in __do_call ret = self.run(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:801: in run return self.forward(*args, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:152: in forward return super(cert_request, self).forward(csr, **options) /usr/lib/python3.6/site-packages/ipaclient/plugins/cert.py:62: in forward result = super(CertRetrieveOverride, self).forward(*args, **options) /usr/lib/python3.6/site-packages/ipalib/frontend.py:824: in forward *args, **kw) /usr/lib/python3.6/site-packages/ipalib/rpc.py :1149: in forward return self._call_command(command, params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1125: in _call_command return command(*params) /usr/lib/python3.6/site-packages/ipalib/rpc.py:1279: in _call return self.__request(name, args) _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ self = name = 'cert_request/1' args = (('-----BEGIN CERTIFICATE REQUEST-----\nMIIC4zCCAcsCAQAwNTEgMB4GA1UEAwwXc2FudGVzdC1ob3N0LTEuaXBhLnRlc3Qx\nETAPBgNVBAoM...profile-subca', 'principal': ipapython.kerberos.Principal('srv/santest-host-1.ipa.test@IPA.TEST'), 'version': '2.229'}) def __request(self, name, args): print_json = self.__verbose >= 2 payload = {'method': unicode(name), 'params': args, 'id': 0} version = args[1].get('version', VERSION_WITHOUT_CAPABILITIES) payload = json_encode_binary( payload, version, pretty_print=print_json) if print_json: logger.info( 'Request: %s', payload ) response = self.__transport.request( self.__host, self.__handler, payload.encode('utf-8'), verbose=self.__verbose >= 3, ) if print_json: logger.info( 'Response: %s', json.dumps(json.loads(response), sort_keys=True, indent=4) ) try: response = json_decode_binary(response) except ValueError as e: raise JSONError(error=str(e)) error = response.get('error') if error: try: error_class = errors_by_code[error['code']] except KeyError: raise UnknownError( code=error.get('code'), error=error.get('message'), server=self.__host, ) else: kw = error.get('data', {}) kw['message'] = error['message'] > raise error_class(**kw) E ipalib.errors.ACIError: Insufficient access: Principal 'srv/santest-host-1.ipa.test@IPA.TEST' is not permitted to use CA 'default-profile-subca' with profile 'caIPAserviceCert' for certificate issuance. /usr/lib/python3.6/site-packages/ipalib/rpc.py:1273: ACIError ------------------------------ Captured log call ------------------------------- rpc.py 1147 INFO [try 1]: Forwarding 'service_add_host/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json rpc.py 1147 INFO [try 1]: Forwarding 'cert_request/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1056 INFO trying https://master.ipa.test/ipa/session/json --------------------------- Captured stdout teardown --------------------------- Ran command: ipaserver.plugins.service.service_del()('srv/santest-host-1.ipa.test@IPA.TEST', version='2.229'): OK Ran command: ipaserver.plugins.service.service_del()('srv/santest-host-2.ipa.test@IPA.TEST', version='2.229'): OK Ran command: ipaserver.plugins.host.host_del()('santest-host-2.ipa.test', version='2.229'): OK Ran command: ipaserver.plugins.host.host_del()('santest-host-1.ipa.test', version='2.229'): OK Ran command: ipaserver.plugins.ca.ca_del()('default-profile-subca', version='2.229'): OK Ran command: ipaserver.plugins.caacl.caacl_del()('default_profile_subca', version='2.229'): OK ---------------------------- Captured log teardown ----------------------------- rpc.py 1147 INFO [try 1]: Forwarding 'service_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'service_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'host_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'host_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'ca_del/1' to json server 'https://master.ipa.test/ipa/session/json' rpc.py 1147 INFO [try 1]: Forwarding 'caacl_del/1' to json server 'https://master.ipa.test/ipa/session/json' ==================== 10 failed, 186 passed in 51.30 seconds ==================== 04-15 19:30 ipadocker.cli ERROR Command ipa-run-tests-3 --ignore test_integration --ignore test_webui --ignore test_ipapython/test_keyring.py -k-test_dns_soa --verbose test_xmlrpc/test_caacl_plugin.py test_xmlrpc/test_caacl_profile_enforcement.py test_xmlrpc/test_cert_plugin.py test_xmlrpc/test_certprofile_plugin.py test_xmlrpc/test_vault_plugin.py failed (exit code 1) 04-15 19:30 ipadocker.command INFO Executing command: chown -R 2000:2000 /freeipa 04-15 19:30 ipadocker.command INFO Executing command: journalctl -b --no-pager > systemd_journal.log 04-15 19:30 ipadocker.command INFO Executing command: tar --ignore-failed-read -cvf /freeipa/var_log.tar /var/log/dirsrv /var/log/httpd /var/log/ipa* /var/log/krb5kdc.log /var/log/pki systemd_journal.log tar: Removing leading `/' from member names tar: Removing leading `/' from hard link targets /var/log/dirsrv/ /var/log/dirsrv/slapd-IPA-TEST/ /var/log/dirsrv/slapd-IPA-TEST/access /var/log/dirsrv/slapd-IPA-TEST/errors /var/log/dirsrv/slapd-IPA-TEST/access.rotationinfo /var/log/dirsrv/slapd-IPA-TEST/audit.rotationinfo /var/log/dirsrv/slapd-IPA-TEST/errors.rotationinfo /var/log/dirsrv/slapd-IPA-TEST/audit /var/log/httpd/ /var/log/httpd/access_log /var/log/httpd/ssl_request_log /var/log/httpd/error_log /var/log/ipa/ /var/log/ipa/renew.log /var/log/ipa/ipactl.log /var/log/ipa/restart.log /var/log/ipa-custodia.audit.log /var/log/ipaclient-install.log /var/log/ipaserver-install.log /var/log/krb5kdc.log /var/log/pki/ /var/log/pki/server/ /var/log/pki/server/upgrade/ /var/log/pki/server/upgrade/10.6.0/ /var/log/pki/server/upgrade/10.6.0/1/ /var/log/pki/server/upgrade/10.6.0/2/ /var/log/pki/pki-server-upgrade-10.6.0.log /var/log/pki/pki-ca-spawn.20180415192137.log /var/log/pki/pki-kra-spawn.20180415192654.log /var/log/pki/pki-tomcat/ /var/log/pki/pki-tomcat/manager.2018-04-15.log /var/log/pki/pki-tomcat/pki/ /var/log/pki/pki-tomcat/pki/debug.2018-04-15.log /var/log/pki/pki-tomcat/localhost_access_log.2018-04-15.txt /var/log/pki/pki-tomcat/localhost.2018-04-15.log /var/log/pki/pki-tomcat/ca/ /var/log/pki/pki-tomcat/ca/system /var/log/pki/pki-tomcat/ca/signedAudit/ /var/log/pki/pki-tomcat/ca/signedAudit/ca_audit /var/log/pki/pki-tomcat/ca/debug.2018-04-15.log /var/log/pki/pki-tomcat/ca/transactions /var/log/pki/pki-tomcat/ca/archive/ /var/log/pki/pki-tomcat/ca/archive/spawn_deployment.cfg.20180415192137 /var/log/pki/pki-tomcat/ca/archive/spawn_manifest.20180415192137 /var/log/pki/pki-tomcat/ca/selftests.log /var/log/pki/pki-tomcat/host-manager.2018-04-15.log /var/log/pki/pki-tomcat/kra/ /var/log/pki/pki-tomcat/kra/system /var/log/pki/pki-tomcat/kra/signedAudit/ /var/log/pki/pki-tomcat/kra/signedAudit/kra_cert-kra_audit /var/log/pki/pki-tomcat/kra/debug.2018-04-15.log /var/log/pki/pki-tomcat/kra/transactions /var/log/pki/pki-tomcat/kra/archive/ /var/log/pki/pki-tomcat/kra/archive/spawn_deployment.cfg.20180415192654 /var/log/pki/pki-tomcat/kra/archive/spawn_manifest.20180415192654 /var/log/pki/pki-tomcat/kra/selftests.log /var/log/pki/pki-tomcat/catalina.2018-04-15.log systemd_journal.log 04-15 19:30 ipadocker.command INFO Executing command: chown 2000:2000 /freeipa/var_log.tar 04-15 19:30 ipadocker.command INFO Executing command: curl --upload /freeipa/var_log.tar https://transfer.sh/var_log.tar % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 0 24.2M 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 17 24.2M 0 0 17 4288k 0 2685k 0:00:09 0:00:01 0:00:08 2683k 100 24.2M 0 0 100 24.2M 0 7224k 0:00:03 0:00:03 - -:--:-- 7224k https://transfer.sh/yZo1Q/var_log.tar 100 24.2M 100 37 100 24.2M 9 6321k 0:00:04 0:00:03 0:00:01 6319k 100 24.2M 100 37 100 24.2M 9 6321k 0:00:04 0:00:03 0:00:01 6319k