Login
[x]
Log in using an account from:
Fedora Account System
Red Hat Associate
Red Hat Customer
Or login using a Red Hat Bugzilla account
Forgot Password
Login:
Hide Forgot
Create an Account
Red Hat Bugzilla – Attachment 873161 Details for
Bug 1075118
Replica installation fails if replica file generated on migrated replica
[?]
New
Simple Search
Advanced Search
My Links
Browse
Requests
Reports
Current State
Search
Tabular reports
Graphical reports
Duplicates
Other Reports
User Changes
Plotly Reports
Bug Status
Bug Severity
Non-Defaults
|
Product Dashboard
Help
Page Help!
Bug Writing Guidelines
What's new
Browser Support Policy
5.0.4.rh83 Release notes
FAQ
Guides index
User guide
Web Services
Contact
Legal
This site requires JavaScript to be enabled to function correctly, please enable it.
ipa replica install log file
ipareplica-install.log (text/plain), 154.50 KB, created by
Kaleem
on 2014-03-11 14:24:03 UTC
(
hide
)
Description:
ipa replica install log file
Filename:
MIME Type:
Creator:
Kaleem
Created:
2014-03-11 14:24:03 UTC
Size:
154.50 KB
patch
obsolete
>2014-03-11T13:32:20Z DEBUG /usr/sbin/ipa-replica-install was invoked with argument "/opt/rhqa_ipa/replica-info-rhel70-replica.testrelm.test.gpg" and options: {'no_forwarders': False, 'conf_ssh': True, 'conf_sshd': True, 'ui_redirect': True, 'reverse_zone': None, 'trust_sshfp': False, 'unattended': True, 'no_host_dns': False, 'mkhomedir': False, 'ip_address': None, 'no_reverse': False, 'setup_dns': True, 'create_sshfp': True, 'setup_ca': True, 'forwarders': [CheckedIPAddress('10.16.65.218')], 'debug': False, 'conf_ntp': True, 'skip_conncheck': False, 'skip_schema_check': False} >2014-03-11T13:32:20Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' >2014-03-11T13:32:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:32:20Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' >2014-03-11T13:32:20Z DEBUG Starting external process >2014-03-11T13:32:20Z DEBUG args=/usr/sbin/httpd -t -D DUMP_VHOSTS >2014-03-11T13:32:20Z DEBUG Process finished, return code=0 >2014-03-11T13:32:20Z DEBUG stdout=VirtualHost configuration: >*:8443 is a NameVirtualHost > default server rhel70-replica.testrelm.test (/etc/httpd/conf.d/nss.conf:86) > port 8443 namevhost rhel70-replica.testrelm.test (/etc/httpd/conf.d/nss.conf:86) > port 8443 namevhost rhel70-replica.testrelm.test (/etc/httpd/conf.d/nss.conf:86) > >2014-03-11T13:32:20Z DEBUG stderr= >2014-03-11T13:32:20Z DEBUG Starting external process >2014-03-11T13:32:20Z DEBUG args=/bin/systemctl is-enabled chronyd.service >2014-03-11T13:32:20Z DEBUG Process finished, return code=1 >2014-03-11T13:32:20Z DEBUG stdout= >2014-03-11T13:32:20Z DEBUG stderr=Failed to issue method call: No such file or directory > >2014-03-11T13:32:20Z DEBUG Starting external process >2014-03-11T13:32:20Z DEBUG args=/bin/systemctl is-active chronyd.service >2014-03-11T13:32:20Z DEBUG Process finished, return code=3 >2014-03-11T13:32:20Z DEBUG stdout=unknown > >2014-03-11T13:32:20Z DEBUG stderr= >2014-03-11T13:32:20Z DEBUG Starting external process >2014-03-11T13:32:20Z DEBUG args=/usr/bin/gpg-agent --batch --homedir /tmp/tmpac7iV9ipa/ipa-3rzq7T/.gnupg --daemon /usr/bin/gpg --batch --homedir /tmp/tmpac7iV9ipa/ipa-3rzq7T/.gnupg --passphrase-fd 0 --yes --no-tty -o /tmp/tmpac7iV9ipa/files.tar -d /opt/rhqa_ipa/replica-info-rhel70-replica.testrelm.test.gpg >2014-03-11T13:32:20Z DEBUG Process finished, return code=0 >2014-03-11T13:32:20Z DEBUG Starting external process >2014-03-11T13:32:20Z DEBUG args=tar xf /tmp/tmpac7iV9ipa/files.tar -C /tmp/tmpac7iV9ipa >2014-03-11T13:32:20Z DEBUG Process finished, return code=0 >2014-03-11T13:32:20Z DEBUG stdout= >2014-03-11T13:32:20Z DEBUG stderr= >2014-03-11T13:32:20Z DEBUG Installing replica file with version 30303 (0 means no version in prepared file). >2014-03-11T13:32:20Z DEBUG Check if rhel70-replica.testrelm.test is a primary hostname for localhost >2014-03-11T13:32:20Z DEBUG Primary hostname for localhost: rhel70-replica.testrelm.test >2014-03-11T13:32:20Z DEBUG Search DNS for rhel70-replica.testrelm.test >2014-03-11T13:32:20Z DEBUG Check if rhel70-replica.testrelm.test is not a CNAME >2014-03-11T13:32:20Z DEBUG Check reverse address of 10.65.207.172 >2014-03-11T13:32:20Z DEBUG Found reverse name: rhel70-replica.testrelm.test >2014-03-11T13:32:20Z DEBUG Check if hp-dc5800-01.testrelm.test is a primary hostname for localhost >2014-03-11T13:32:20Z DEBUG Primary hostname for localhost: hp-dc5800-01.testrelm.test >2014-03-11T13:32:20Z DEBUG Search DNS for hp-dc5800-01.testrelm.test >2014-03-11T13:32:20Z DEBUG Check if hp-dc5800-01.testrelm.test is not a CNAME >2014-03-11T13:32:20Z DEBUG Check reverse address of 10.16.65.218 >2014-03-11T13:32:20Z DEBUG Found reverse name: hp-dc5800-01.testrelm.test >2014-03-11T13:32:20Z DEBUG Starting external process >2014-03-11T13:32:20Z DEBUG args=/usr/sbin/ipa-replica-conncheck --master hp-dc5800-01.testrelm.test --auto-master-check --realm TESTRELM.TEST --principal admin --hostname rhel70-replica.testrelm.test --password XXXXXXXX >2014-03-11T13:32:35Z DEBUG Process finished, return code=0 >2014-03-11T13:32:35Z DEBUG Starting external process >2014-03-11T13:32:35Z DEBUG args=/sbin/ip -family inet -oneline address show >2014-03-11T13:32:35Z DEBUG Process finished, return code=0 >2014-03-11T13:32:35Z DEBUG stdout=1: lo inet 127.0.0.1/8 scope host lo\ valid_lft forever preferred_lft forever >2: eth0 inet 10.65.207.172/23 brd 10.65.207.255 scope global dynamic eth0\ valid_lft 84031sec preferred_lft 84031sec > >2014-03-11T13:32:35Z DEBUG stderr= >2014-03-11T13:32:35Z DEBUG importing all plugin modules in '/usr/lib/python2.7/site-packages/ipalib/plugins'... >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/aci.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/automember.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/automount.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/baseldap.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/batch.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/cert.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/config.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/delegation.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/dns.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/group.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbacrule.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbacsvc.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbacsvcgroup.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hbactest.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/host.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/hostgroup.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/idrange.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/internal.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/kerberos.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/krbtpolicy.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/migration.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/misc.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/netgroup.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/passwd.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/permission.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/ping.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/pkinit.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/privilege.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/pwpolicy.py' >2014-03-11T13:32:35Z DEBUG Starting external process >2014-03-11T13:32:35Z DEBUG args=klist -V >2014-03-11T13:32:35Z DEBUG Process finished, return code=0 >2014-03-11T13:32:35Z DEBUG stdout=Kerberos 5 version 1.11.3 > >2014-03-11T13:32:35Z DEBUG stderr= >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/realmdomains.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/role.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/selfservice.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/selinuxusermap.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/service.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/sudocmd.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/sudocmdgroup.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/sudorule.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/trust.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/user.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/virtual.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipalib/plugins/xmlclient.py' >2014-03-11T13:32:35Z DEBUG importing all plugin modules in '/usr/lib/python2.7/site-packages/ipaserver/install/plugins'... >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/adtrust.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/baseupdate.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/dns.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/fix_replica_agreements.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/rename_managed.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/update_anonymous_aci.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/update_idranges.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/update_pacs.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/update_services.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/updateclient.py' >2014-03-11T13:32:35Z DEBUG importing plugin module '/usr/lib/python2.7/site-packages/ipaserver/install/plugins/upload_cacrt.py' >2014-03-11T13:32:36Z DEBUG DS group dirsrv exists >2014-03-11T13:32:36Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:32:38Z DEBUG Created connection context.ldap2_46478544 >2014-03-11T13:32:40Z DEBUG flushing ldaps://hp-dc5800-01.testrelm.test from SchemaCache >2014-03-11T13:32:40Z DEBUG retrieving schema for SchemaCache url=ldaps://hp-dc5800-01.testrelm.test conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x2c5e248> >2014-03-11T13:32:49Z DEBUG Created connection context.ldap2 >2014-03-11T13:32:49Z DEBUG flushing ldaps://hp-dc5800-01.testrelm.test from SchemaCache >2014-03-11T13:32:49Z DEBUG retrieving schema for SchemaCache url=ldaps://hp-dc5800-01.testrelm.test conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x43d1368> >2014-03-11T13:32:55Z DEBUG Destroyed connection context.ldap2 >2014-03-11T13:32:55Z DEBUG Check forward/reverse DNS resolution >2014-03-11T13:32:55Z DEBUG Search DNS server hp-xw9400-02.testrelm.test (['10.16.65.44', '10.16.65.44', '10.16.65.44']) for hp-dc5800-01.testrelm.test >2014-03-11T13:32:55Z DEBUG Check reverse address 10.16.65.218 (hp-dc5800-01.testrelm.test) >2014-03-11T13:32:56Z DEBUG Address 10.16.65.218 resolves to: hp-dc5800-01.testrelm.test.. >2014-03-11T13:32:56Z DEBUG Search DNS server hp-xw9400-02.testrelm.test (['10.16.65.44', '10.16.65.44', '10.16.65.44']) for rhel70-replica.testrelm.test >2014-03-11T13:32:57Z DEBUG Check reverse address 10.65.207.172 (rhel70-replica.testrelm.test) >2014-03-11T13:32:57Z DEBUG Address 10.65.207.172 resolves to: rhel70-replica.testrelm.test.. >2014-03-11T13:32:58Z DEBUG Destroyed connection context.ldap2_46478544 >2014-03-11T13:32:58Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:32:58Z DEBUG Installing CA Replica from master with a merged database >2014-03-11T13:32:58Z DEBUG Starting external process >2014-03-11T13:32:58Z DEBUG args=/bin/systemctl is-enabled chronyd.service >2014-03-11T13:32:58Z DEBUG Process finished, return code=1 >2014-03-11T13:32:58Z DEBUG stdout= >2014-03-11T13:32:58Z DEBUG stderr=Failed to issue method call: No such file or directory > >2014-03-11T13:32:58Z DEBUG Starting external process >2014-03-11T13:32:58Z DEBUG args=/bin/systemctl is-active chronyd.service >2014-03-11T13:32:58Z DEBUG Process finished, return code=3 >2014-03-11T13:32:58Z DEBUG stdout=unknown > >2014-03-11T13:32:58Z DEBUG stderr= >2014-03-11T13:32:58Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:32:58Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' >2014-03-11T13:32:58Z DEBUG Configuring NTP daemon (ntpd) >2014-03-11T13:32:58Z DEBUG [1/4]: stopping ntpd >2014-03-11T13:32:58Z DEBUG Starting external process >2014-03-11T13:32:58Z DEBUG args=/bin/systemctl is-active ntpd.service >2014-03-11T13:32:58Z DEBUG Process finished, return code=3 >2014-03-11T13:32:58Z DEBUG stdout=unknown > >2014-03-11T13:32:58Z DEBUG stderr= >2014-03-11T13:32:58Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:32:58Z DEBUG Starting external process >2014-03-11T13:32:58Z DEBUG args=/bin/systemctl stop ntpd.service >2014-03-11T13:32:58Z DEBUG Process finished, return code=0 >2014-03-11T13:32:58Z DEBUG stdout= >2014-03-11T13:32:58Z DEBUG stderr= >2014-03-11T13:32:58Z DEBUG duration: 0 seconds >2014-03-11T13:32:58Z DEBUG [2/4]: writing configuration >2014-03-11T13:32:58Z DEBUG Backing up system configuration file '/etc/ntp.conf' >2014-03-11T13:32:58Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' >2014-03-11T13:32:58Z DEBUG Backing up system configuration file '/etc/sysconfig/ntpd' >2014-03-11T13:32:58Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' >2014-03-11T13:32:58Z DEBUG duration: 0 seconds >2014-03-11T13:32:58Z DEBUG [3/4]: configuring ntpd to start on boot >2014-03-11T13:32:58Z DEBUG Starting external process >2014-03-11T13:32:58Z DEBUG args=/bin/systemctl is-enabled ntpd.service >2014-03-11T13:32:58Z DEBUG Process finished, return code=1 >2014-03-11T13:32:58Z DEBUG stdout=disabled > >2014-03-11T13:32:58Z DEBUG stderr= >2014-03-11T13:32:58Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:32:58Z DEBUG Starting external process >2014-03-11T13:32:58Z DEBUG args=/bin/systemctl enable ntpd.service >2014-03-11T13:32:58Z DEBUG Process finished, return code=0 >2014-03-11T13:32:58Z DEBUG stdout= >2014-03-11T13:32:58Z DEBUG stderr=ln -s '/usr/lib/systemd/system/ntpd.service' '/etc/systemd/system/multi-user.target.wants/ntpd.service' > >2014-03-11T13:32:58Z DEBUG duration: 0 seconds >2014-03-11T13:32:58Z DEBUG [4/4]: starting ntpd >2014-03-11T13:32:58Z DEBUG Starting external process >2014-03-11T13:32:58Z DEBUG args=/bin/systemctl start ntpd.service >2014-03-11T13:32:58Z DEBUG Process finished, return code=0 >2014-03-11T13:32:58Z DEBUG stdout= >2014-03-11T13:32:58Z DEBUG stderr= >2014-03-11T13:32:58Z DEBUG Starting external process >2014-03-11T13:32:58Z DEBUG args=/bin/systemctl is-active ntpd.service >2014-03-11T13:32:58Z DEBUG Process finished, return code=0 >2014-03-11T13:32:58Z DEBUG stdout=active > >2014-03-11T13:32:58Z DEBUG stderr= >2014-03-11T13:32:58Z DEBUG duration: 0 seconds >2014-03-11T13:32:58Z DEBUG Done configuring NTP daemon (ntpd). >2014-03-11T13:32:58Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:32:58Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' >2014-03-11T13:32:58Z DEBUG Configuring directory server (dirsrv): Estimated time 31 minutes >2014-03-11T13:32:58Z DEBUG [1/34]: creating directory server user >2014-03-11T13:32:58Z DEBUG DS user dirsrv exists >2014-03-11T13:32:58Z DEBUG duration: 0 seconds >2014-03-11T13:32:58Z DEBUG [2/34]: creating directory server instance >2014-03-11T13:32:58Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:32:58Z DEBUG Backing up system configuration file '/etc/sysconfig/dirsrv' >2014-03-11T13:32:58Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' >2014-03-11T13:32:58Z DEBUG >dn: dc=testrelm,dc=test >objectClass: top >objectClass: domain >objectClass: pilotObject >dc: testrelm >info: IPA V2.0 > >2014-03-11T13:32:58Z DEBUG writing inf template >2014-03-11T13:32:58Z DEBUG >[General] >FullMachineName= rhel70-replica.testrelm.test >SuiteSpotUserID= dirsrv >SuiteSpotGroup= dirsrv >ServerRoot= /usr/lib64/dirsrv >[slapd] >ServerPort= 389 >ServerIdentifier= TESTRELM-TEST >Suffix= dc=testrelm,dc=test >RootDN= cn=Directory Manager >InstallLdifFile= /var/lib/dirsrv/boot.ldif >inst_dir= /var/lib/dirsrv/scripts-TESTRELM-TEST > >2014-03-11T13:32:58Z DEBUG calling setup-ds.pl >2014-03-11T13:32:58Z DEBUG Starting external process >2014-03-11T13:32:58Z DEBUG args=/usr/sbin/setup-ds.pl --silent --logfile - -f /tmp/tmprSpjQr >2014-03-11T13:33:00Z DEBUG Process finished, return code=0 >2014-03-11T13:33:00Z DEBUG stdout=[14/03/11:19:03:00] - [Setup] Info Your new DS instance 'TESTRELM-TEST' was successfully created. >Your new DS instance 'TESTRELM-TEST' was successfully created. >[14/03/11:19:03:00] - [Setup] Success Exiting . . . >Log file is '-' > >Exiting . . . >Log file is '-' > > >2014-03-11T13:33:00Z DEBUG stderr= >2014-03-11T13:33:00Z DEBUG completed creating ds instance >2014-03-11T13:33:00Z DEBUG restarting ds instance >2014-03-11T13:33:00Z DEBUG Starting external process >2014-03-11T13:33:00Z DEBUG args=/bin/systemctl --system daemon-reload >2014-03-11T13:33:00Z DEBUG Process finished, return code=0 >2014-03-11T13:33:00Z DEBUG stdout= >2014-03-11T13:33:00Z DEBUG stderr= >2014-03-11T13:33:00Z DEBUG Starting external process >2014-03-11T13:33:00Z DEBUG args=/bin/systemctl restart dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:00Z DEBUG Process finished, return code=0 >2014-03-11T13:33:00Z DEBUG stdout= >2014-03-11T13:33:00Z DEBUG stderr= >2014-03-11T13:33:00Z DEBUG Starting external process >2014-03-11T13:33:00Z DEBUG args=/bin/systemctl is-active dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:00Z DEBUG Process finished, return code=0 >2014-03-11T13:33:00Z DEBUG stdout=active > >2014-03-11T13:33:00Z DEBUG stderr= >2014-03-11T13:33:00Z DEBUG wait_for_open_ports: localhost [389] timeout 300 >2014-03-11T13:33:01Z DEBUG Starting external process >2014-03-11T13:33:01Z DEBUG args=/bin/systemctl is-active dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:01Z DEBUG Process finished, return code=0 >2014-03-11T13:33:01Z DEBUG stdout=active > >2014-03-11T13:33:01Z DEBUG stderr= >2014-03-11T13:33:01Z DEBUG done restarting ds instance >2014-03-11T13:33:01Z DEBUG duration: 3 seconds >2014-03-11T13:33:01Z DEBUG [3/34]: adding default schema >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [4/34]: enabling memberof plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/memberof-conf.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpivPMWG >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=replace nsslapd-pluginenabled: > on >add memberofgroupattr: > memberUser >add memberofgroupattr: > memberHost >modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [5/34]: enabling winsync plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/ipa-winsync-conf.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpYACWTZ >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectclass: > top > nsSlapdPlugin > extensibleObject >add cn: > ipa-winsync >add nsslapd-pluginpath: > libipa_winsync >add nsslapd-plugininitfunc: > ipa_winsync_plugin_init >add nsslapd-pluginDescription: > Allows IPA to work with the DS windows sync feature >add nsslapd-pluginid: > ipa-winsync >add nsslapd-pluginversion: > 1.0 >add nsslapd-pluginvendor: > Red Hat >add nsslapd-plugintype: > preoperation >add nsslapd-pluginenabled: > on >add nsslapd-plugin-depends-on-type: > database >add ipaWinSyncRealmFilter: > (objectclass=krbRealmContainer) >add ipaWinSyncRealmAttr: > cn >add ipaWinSyncNewEntryFilter: > (cn=ipaConfig) >add ipaWinSyncNewUserOCAttr: > ipauserobjectclasses >add ipaWinSyncUserFlatten: > true >add ipaWinsyncHomeDirAttr: > ipaHomesRootDir >add ipaWinsyncLoginShellAttr: > ipaDefaultLoginShell >add ipaWinSyncDefaultGroupAttr: > ipaDefaultPrimaryGroup >add ipaWinSyncDefaultGroupFilter: > (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) >add ipaWinSyncAcctDisable: > both >add ipaWinSyncForceSync: > true >add ipaWinSyncUserAttr: > uidNumber -1 > gidNumber -1 >adding new entry "cn=ipa-winsync,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [6/34]: configuring replication version plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/version-conf.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpmlE7S0 >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectclass: > top > nsSlapdPlugin > extensibleObject >add cn: > IPA Version Replication >add nsslapd-pluginpath: > libipa_repl_version >add nsslapd-plugininitfunc: > repl_version_plugin_init >add nsslapd-plugintype: > preoperation >add nsslapd-pluginenabled: > off >add nsslapd-pluginid: > ipa_repl_version >add nsslapd-pluginversion: > 1.0 >add nsslapd-pluginvendor: > Red Hat, Inc. >add nsslapd-plugindescription: > IPA Replication version plugin >add nsslapd-plugin-depends-on-type: > database >add nsslapd-plugin-depends-on-named: > Multimaster Replication Plugin >adding new entry "cn=IPA Version Replication,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [7/34]: enabling IPA enrollment plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpLX9TqE -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpzoUXSr >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectclass: > top > nsSlapdPlugin > extensibleObject >add cn: > ipa_enrollment_extop >add nsslapd-pluginpath: > libipa_enrollment_extop >add nsslapd-plugininitfunc: > ipaenrollment_init >add nsslapd-plugintype: > extendedop >add nsslapd-pluginenabled: > on >add nsslapd-pluginid: > ipa_enrollment_extop >add nsslapd-pluginversion: > 1.0 >add nsslapd-pluginvendor: > RedHat >add nsslapd-plugindescription: > Enroll hosts into the IPA domain >add nsslapd-plugin-depends-on-type: > database >add nsslapd-realmTree: > dc=testrelm,dc=test >adding new entry "cn=ipa_enrollment_extop,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [8/34]: enabling ldapi >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpeTtBtR -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpd5F87A >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=replace nsslapd-ldapilisten: > on >modifying entry "cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [9/34]: configuring uniqueness plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmp7KNOH_ -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmptKhdDo >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectClass: > top > nsSlapdPlugin > extensibleObject >add cn: > krbPrincipalName uniqueness >add nsslapd-pluginPath: > libattr-unique-plugin >add nsslapd-pluginInitfunc: > NSUniqueAttr_Init >add nsslapd-pluginType: > preoperation >add nsslapd-pluginEnabled: > on >add nsslapd-pluginarg0: > krbPrincipalName >add nsslapd-pluginarg1: > dc=testrelm,dc=test >add nsslapd-plugin-depends-on-type: > database >add nsslapd-pluginId: > NSUniqueAttr >add nsslapd-pluginVersion: > 1.1.0 >add nsslapd-pluginVendor: > Fedora Project >add nsslapd-pluginDescription: > Enforce unique attribute values >adding new entry "cn=krbPrincipalName uniqueness,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsSlapdPlugin > extensibleObject >add cn: > krbCanonicalName uniqueness >add nsslapd-pluginPath: > libattr-unique-plugin >add nsslapd-pluginInitfunc: > NSUniqueAttr_Init >add nsslapd-pluginType: > preoperation >add nsslapd-pluginEnabled: > on >add nsslapd-pluginarg0: > krbCanonicalName >add nsslapd-pluginarg1: > dc=testrelm,dc=test >add nsslapd-plugin-depends-on-type: > database >add nsslapd-pluginId: > NSUniqueAttr >add nsslapd-pluginVersion: > 1.1.0 >add nsslapd-pluginVendor: > Fedora Project >add nsslapd-pluginDescription: > Enforce unique attribute values >adding new entry "cn=krbCanonicalName uniqueness,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsSlapdPlugin > extensibleObject >add cn: > netgroup uniqueness >add nsslapd-pluginPath: > libattr-unique-plugin >add nsslapd-pluginInitfunc: > NSUniqueAttr_Init >add nsslapd-pluginType: > preoperation >add nsslapd-pluginEnabled: > on >add nsslapd-pluginarg0: > cn >add nsslapd-pluginarg1: > cn=ng,cn=alt,dc=testrelm,dc=test >add nsslapd-plugin-depends-on-type: > database >add nsslapd-pluginId: > NSUniqueAttr >add nsslapd-pluginVersion: > 1.1.0 >add nsslapd-pluginVendor: > Fedora Project >add nsslapd-pluginDescription: > Enforce unique attribute values >adding new entry "cn=netgroup uniqueness,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsSlapdPlugin > extensibleObject >add cn: > ipaUniqueID uniqueness >add nsslapd-pluginPath: > libattr-unique-plugin >add nsslapd-pluginInitfunc: > NSUniqueAttr_Init >add nsslapd-pluginType: > preoperation >add nsslapd-pluginEnabled: > on >add nsslapd-pluginarg0: > ipaUniqueID >add nsslapd-pluginarg1: > dc=testrelm,dc=test >add nsslapd-plugin-depends-on-type: > database >add nsslapd-pluginId: > NSUniqueAttr >add nsslapd-pluginVersion: > 1.1.0 >add nsslapd-pluginVendor: > Fedora Project >add nsslapd-pluginDescription: > Enforce unique attribute values >adding new entry "cn=ipaUniqueID uniqueness,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsSlapdPlugin > extensibleObject >add cn: > sudorule name uniqueness >add nsslapd-pluginDescription: > Enforce unique attribute values >add nsslapd-pluginPath: > libattr-unique-plugin >add nsslapd-pluginInitfunc: > NSUniqueAttr_Init >add nsslapd-pluginType: > preoperation >add nsslapd-pluginEnabled: > on >add nsslapd-pluginarg0: > cn >add nsslapd-pluginarg1: > cn=sudorules,cn=sudo,dc=testrelm,dc=test >add nsslapd-plugin-depends-on-type: > database >add nsslapd-pluginId: > NSUniqueAttr >add nsslapd-pluginVersion: > 1.1.0 >add nsslapd-pluginVendor: > Fedora Project >adding new entry "cn=sudorule name uniqueness,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [10/34]: configuring uuid plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/uuid-conf.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmp7CefMJ >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectclass: > top > nsSlapdPlugin > extensibleObject >add cn: > IPA UUID >add nsslapd-pluginpath: > libipa_uuid >add nsslapd-plugininitfunc: > ipauuid_init >add nsslapd-plugintype: > preoperation >add nsslapd-pluginenabled: > on >add nsslapd-pluginid: > ipauuid_version >add nsslapd-pluginversion: > 1.0 >add nsslapd-pluginvendor: > Red Hat, Inc. >add nsslapd-plugindescription: > IPA UUID plugin >add nsslapd-plugin-depends-on-type: > database >adding new entry "cn=IPA UUID,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpquCMXm -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpswnTGb >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectclass: > top > extensibleObject >add cn: > IPA Unique IDs >add ipaUuidAttr: > ipaUniqueID >add ipaUuidMagicRegen: > autogenerate >add ipaUuidFilter: > (|(objectclass=ipaObject)(objectclass=ipaAssociation)) >add ipaUuidScope: > dc=testrelm,dc=test >add ipaUuidEnforce: > TRUE >adding new entry "cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [11/34]: configuring modrdn plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/modrdn-conf.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpvCiA2I >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectclass: > top > nsSlapdPlugin > extensibleObject >add cn: > IPA MODRDN >add nsslapd-pluginpath: > libipa_modrdn >add nsslapd-plugininitfunc: > ipamodrdn_init >add nsslapd-plugintype: > betxnpostoperation >add nsslapd-pluginenabled: > on >add nsslapd-pluginid: > ipamodrdn_version >add nsslapd-pluginversion: > 1.0 >add nsslapd-pluginvendor: > Red Hat, Inc. >add nsslapd-plugindescription: > IPA MODRDN plugin >add nsslapd-plugin-depends-on-type: > database >add nsslapd-pluginPrecedence: > 60 >adding new entry "cn=IPA MODRDN,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpPoB1ax -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpFOL8PX >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectclass: > top > extensibleObject >add cn: > Kerberos Principal Name >add ipaModRDNsourceAttr: > uid >add ipaModRDNtargetAttr: > krbPrincipalName >add ipaModRDNsuffix: > @TESTRELM.TEST >add ipaModRDNfilter: > (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) >add ipaModRDNscope: > dc=testrelm,dc=test >adding new entry "cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [12/34]: configuring DNS plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/ipa-dns-conf.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpW0UqwP >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectclass: > top > nsslapdPlugin > extensibleObject >add cn: > IPA DNS >add nsslapd-plugindescription: > IPA DNS support plugin >add nsslapd-pluginenabled: > on >add nsslapd-pluginid: > ipa_dns >add nsslapd-plugininitfunc: > ipadns_init >add nsslapd-pluginpath: > libipa_dns.so >add nsslapd-plugintype: > preoperation >add nsslapd-pluginvendor: > Red Hat, Inc. >add nsslapd-pluginversion: > 1.0 >add nsslapd-plugin-depends-on-type: > database >adding new entry "cn=IPA DNS,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [13/34]: enabling entryUSN plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/entryusn.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpbE5gju >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=replace nsslapd-entryusn-global: > on >modifying entry "cn=config" >modify complete > >replace nsslapd-entryusn-import-initval: > next >modifying entry "cn=config" >modify complete > >replace nsslapd-pluginenabled: > on >modifying entry "cn=USN,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [14/34]: configuring lockout plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/lockout-conf.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpxNEBGy >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectclass: > top > nsSlapdPlugin > extensibleObject >add cn: > IPA Lockout >add nsslapd-pluginpath: > libipa_lockout >add nsslapd-plugininitfunc: > ipalockout_init >add nsslapd-plugintype: > object >add nsslapd-pluginenabled: > on >add nsslapd-pluginid: > ipalockout_version >add nsslapd-pluginversion: > 1.0 >add nsslapd-pluginvendor: > Red Hat, Inc. >add nsslapd-plugindescription: > IPA Lockout plugin >add nsslapd-plugin-depends-on-type: > database >adding new entry "cn=IPA Lockout,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [15/34]: creating indices >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/indices.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpaLM5Qu >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=add objectClass: > top > nsIndex >add cn: > krbPrincipalName >add nsSystemIndex: > false >add nsIndexType: > eq > sub >adding new entry "cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsIndex >add cn: > ou >add nsSystemIndex: > false >add nsIndexType: > eq > sub >adding new entry "cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsIndex >add cn: > carLicense >add nsSystemIndex: > false >add nsIndexType: > eq > sub >adding new entry "cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsIndex >add cn: > title >add nsSystemIndex: > false >add nsIndexType: > eq > sub >adding new entry "cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsIndex >add cn: > manager >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsIndex >add cn: > secretary >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsIndex >add cn: > displayname >add nsSystemIndex: > false >add nsIndexType: > eq > sub >adding new entry "cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add nsIndexType: > sub >modifying entry "cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsIndex >add cn: > uidnumber >add nsSystemIndex: > false >add nsIndexType: > eq >add nsMatchingRule: > integerOrderingMatch >adding new entry "cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add objectClass: > top > nsIndex >add cn: > gidnumber >add nsSystemIndex: > false >add nsIndexType: > eq >add nsMatchingRule: > integerOrderingMatch >adding new entry "cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >replace nsIndexType: > eq,pres >modifying entry "cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >replace nsIndexType: > eq,pres >modifying entry "cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add ObjectClass: > top > nsIndex >add cn: > fqdn >add nsSystemIndex: > false >add nsIndexType: > eq > pres >adding new entry "cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add ObjectClass: > top > nsIndex >add cn: > macAddress >add nsSystemIndex: > false >add nsIndexType: > eq > pres >adding new entry "cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > memberHost >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > memberUser >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > sourcehost >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > memberservice >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > managedby >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > memberallowcmd >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > memberdenycmd >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > ipasudorunas >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > ipasudorunasgroup >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq > pres > sub >adding new entry "cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > automountkey >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq >adding new entry "cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > ipakrbprincipalalias >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq >adding new entry "cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add cn: > ipauniqueid >add ObjectClass: > top > nsIndex >add nsSystemIndex: > false >add nsIndexType: > eq >adding new entry "cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [16/34]: enabling referential integrity plugin >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/referint-conf.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmppzscba >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=replace nsslapd-pluginenabled: > on >add nsslapd-pluginArg7: > manager >add nsslapd-pluginArg8: > secretary >add nsslapd-pluginArg9: > memberuser >add nsslapd-pluginArg10: > memberhost >add nsslapd-pluginArg11: > sourcehost >add nsslapd-pluginArg12: > memberservice >add nsslapd-pluginArg13: > managedby >add nsslapd-pluginArg14: > memberallowcmd >add nsslapd-pluginArg15: > memberdenycmd >add nsslapd-pluginArg16: > ipasudorunas >add nsslapd-pluginArg17: > ipasudorunasgroup >modifying entry "cn=referential integrity postoperation,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:02Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:02Z DEBUG duration: 0 seconds >2014-03-11T13:33:02Z DEBUG [17/34]: configuring ssl for ds instance >2014-03-11T13:33:02Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -N -f /etc/dirsrv/slapd-TESTRELM-TEST//pwdfile.txt >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/pk12util -d /etc/dirsrv/slapd-TESTRELM-TEST/ -i /tmp/tmpac7iV9ipa/realm_info/dscert.p12 -k /etc/dirsrv/slapd-TESTRELM-TEST//pwdfile.txt -v -w /dev/stdin >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -L >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >Certificate Nickname Trust Attributes > SSL,S/MIME,JAR/XPI > >Server-Cert u,u,u >TESTRELM.TEST IPA CA ,, > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -A -n CA -t CT,CT, -a >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -L >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >Certificate Nickname Trust Attributes > SSL,S/MIME,JAR/XPI > >Server-Cert u,u,u >TESTRELM.TEST IPA CA CT,C, > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -M -n TESTRELM.TEST IPA CA -t CT,CT, >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -O -n Server-Cert >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout="TESTRELM.TEST IPA CA" [CN=Certificate Authority,O=TESTRELM.TEST] > > "Server-Cert" [CN=rhel70-replica.testrelm.test,O=TESTRELM.TEST] > > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -L -n TESTRELM.TEST IPA CA -a >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=-----BEGIN CERTIFICATE----- >MIIDmjCCAoKgAwIBAgIBATANBgkqhkiG9w0BAQsFADA4MRYwFAYDVQQKEw1URVNU >UkVMTS5URVNUMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMTQw >MzExMTA1OTE5WhcNMzQwMzExMTA1OTE5WjA4MRYwFAYDVQQKEw1URVNUUkVMTS5U >RVNUMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwggEiMA0GCSqGSIb3 >DQEBAQUAA4IBDwAwggEKAoIBAQCnJ9uk9L1EbAwOWQQQ6JSfBsYHdL8RpVsACmaT >pSME178J9h1uw9qRDylKdv/NYbo3Hgvy1fCyi/K27xyO8ZDhnoCWXVOmMY/E31SE >eKO/Bl9Dssvm5kPoHYoX03VGgZq0gGTterWQCDEKt9tu2G2O/sS3j/IaerKCeZ5C >7Ez9fAJhzDiuPKIzjhw2My/FDa3gTiIxvLnuceCSpGnjUV6u510sgbsjc9ac9pqd >r6km3LPN2+FsSszr9dpKDtFIsJdOpb7A7FFUEtt+fbk4ctMHQhYpq839aowuyAFh >VJtVDQu+SNLvHe7ZWwYn7syOb6THJRtiB4mllFklJD0/TB1FAgMBAAGjga4wgasw >HwYDVR0jBBgwFoAUUUM5diaKnjPZX9fbprNp5mOhhgUwDwYDVR0TAQH/BAUwAwEB >/zAOBgNVHQ8BAf8EBAMCAcYwHQYDVR0OBBYEFFFDOXYmip4z2V/X26azaeZjoYYF >MEgGCCsGAQUFBwEBBDwwOjA4BggrBgEFBQcwAYYsaHR0cDovL2hwLXh3OTQwMC0w >Mi50ZXN0cmVsbS50ZXN0OjgwL2NhL29jc3AwDQYJKoZIhvcNAQELBQADggEBAJUh >vM5K6SspEOVBgXOaKlwJYdwZ+Arp5A/tT/l2+wjYsK/WudKleMcwzgkREIBYOywy >oJ7yh1UM+h4c1B2c7WcvVm0pdhM8mMI2M59GprXE8WhiwaPLJ2aNB1eGO8NVhc+G >GpzZlnnSdKUw3vFLK+RsJ8Lqeb9bwLw3H+awn5S/5u2otq5qDjDDKNtnO+rgWJn9 >EuZBvsCUcOghgZE6Sg9/a3Yj2N0BMACjj93HNuAL/atBlgtUND+ulZQH9+NZVdks >B7sp/9vChNDSdjd6+2eXYvh891Nl5EzgZfEItMW0VP1oHrrDPiDv2Zc6806bONoK >qt3ICeKTnZskYRV504Y= >-----END CERTIFICATE----- > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -L -n Server-Cert -a >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=-----BEGIN CERTIFICATE----- >MIIEJTCCAw2gAwIBAgIED/8ACTANBgkqhkiG9w0BAQsFADA4MRYwFAYDVQQKEw1U >RVNUUkVMTS5URVNUMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcN >MTQwMzExMTMzMTA5WhcNMTYwMzExMTMzMTA5WjA/MRYwFAYDVQQKEw1URVNUUkVM >TS5URVNUMSUwIwYDVQQDExxyaGVsNzAtcmVwbGljYS50ZXN0cmVsbS50ZXN0MIIB >IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwgSWWTnwhdj8Abm22uXZNn8O >/g6wm6zh7dJqbzXPJVcPI/GqBYzUqCPGSslt9viLt5SEsBKc2oZBU7xso7pEd2aQ >ThLXPjOo3LC1IiViFbRcDhQiKWLeSl5Ch+u6Yc9wwSdLHP5bicjkYpusM5PuCPrG >N1cQ3zMvX5zbXuW/5NIZ4yYQEdtMFJxAsXicjw9mVGKSYc0ttad5sv4yiSer0nph >6LDYbiXcg8u8jPYuovkbI/IpMxbd/Jbytj4NPWks5ljQ9iiixsjQWrvb8tNJugzL >MxlMx3eOxXENb1pCH2N9+7I1GXwvh857RSPqVb/u/OpVhYmXlfO1R7NZtpJTcQID >AQABo4IBLjCCASowHwYDVR0jBBgwFoAUUUM5diaKnjPZX9fbprNp5mOhhgUwPwYI >KwYBBQUHAQEEMzAxMC8GCCsGAQUFBzABhiNodHRwOi8vaXBhLWNhLnRlc3RyZWxt >LnRlc3QvY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBPAwHQYDVR0lBBYwFAYIKwYBBQUH >AwEGCCsGAQUFBwMCMHgGA1UdHwRxMG8wbaA1oDOGMWh0dHA6Ly9pcGEtY2EudGVz >dHJlbG0udGVzdC9pcGEvY3JsL01hc3RlckNSTC5iaW6iNKQyMDAxDjAMBgNVBAoT >BWlwYWNhMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHQYDVR0OBBYE >FFryJmr9i6CPao8bkS6X3CsCScF+MA0GCSqGSIb3DQEBCwUAA4IBAQAKVMZFs7OI >67fmDhrcNwGzfMJZEJtK8MWVrwnlVjNVWjAM0byeLNKn538jiKd02O0Pp9QBmqoJ >JQeKnFByhiP9WbL47+hZ3trx2+vLjzHrZ7YLq5WN8kB5j1/v4HeZAR/HYPlmsB7X >8/mAtpfBEr5vSdRYPZlw7EiEiLP5dQhkcFIakWDLXurB+sDXPb1rchMG9g9/YPu3 >FR4oHM/o/66d03sFUwDMERQ5OYbRSY8qHLB8LDLMRstjEfGVQg/eG3RlVT/7yETh >gAMW2D+pFUHqe5QItxyOHyZ0FU0ak2qXO9BrjaQR4sHlQGO3tpPcRLalEhnrdluf >HBcKw9HQ85HY >-----END CERTIFICATE----- > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -L >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >Certificate Nickname Trust Attributes > SSL,S/MIME,JAR/XPI > >Server-Cert u,u,u >TESTRELM.TEST IPA CA CT,C, > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -L -n Server-Cert -a >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=-----BEGIN CERTIFICATE----- >MIIEJTCCAw2gAwIBAgIED/8ACTANBgkqhkiG9w0BAQsFADA4MRYwFAYDVQQKEw1U >RVNUUkVMTS5URVNUMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcN >MTQwMzExMTMzMTA5WhcNMTYwMzExMTMzMTA5WjA/MRYwFAYDVQQKEw1URVNUUkVM >TS5URVNUMSUwIwYDVQQDExxyaGVsNzAtcmVwbGljYS50ZXN0cmVsbS50ZXN0MIIB >IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwgSWWTnwhdj8Abm22uXZNn8O >/g6wm6zh7dJqbzXPJVcPI/GqBYzUqCPGSslt9viLt5SEsBKc2oZBU7xso7pEd2aQ >ThLXPjOo3LC1IiViFbRcDhQiKWLeSl5Ch+u6Yc9wwSdLHP5bicjkYpusM5PuCPrG >N1cQ3zMvX5zbXuW/5NIZ4yYQEdtMFJxAsXicjw9mVGKSYc0ttad5sv4yiSer0nph >6LDYbiXcg8u8jPYuovkbI/IpMxbd/Jbytj4NPWks5ljQ9iiixsjQWrvb8tNJugzL >MxlMx3eOxXENb1pCH2N9+7I1GXwvh857RSPqVb/u/OpVhYmXlfO1R7NZtpJTcQID >AQABo4IBLjCCASowHwYDVR0jBBgwFoAUUUM5diaKnjPZX9fbprNp5mOhhgUwPwYI >KwYBBQUHAQEEMzAxMC8GCCsGAQUFBzABhiNodHRwOi8vaXBhLWNhLnRlc3RyZWxt >LnRlc3QvY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBPAwHQYDVR0lBBYwFAYIKwYBBQUH >AwEGCCsGAQUFBwMCMHgGA1UdHwRxMG8wbaA1oDOGMWh0dHA6Ly9pcGEtY2EudGVz >dHJlbG0udGVzdC9pcGEvY3JsL01hc3RlckNSTC5iaW6iNKQyMDAxDjAMBgNVBAoT >BWlwYWNhMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHQYDVR0OBBYE >FFryJmr9i6CPao8bkS6X3CsCScF+MA0GCSqGSIb3DQEBCwUAA4IBAQAKVMZFs7OI >67fmDhrcNwGzfMJZEJtK8MWVrwnlVjNVWjAM0byeLNKn538jiKd02O0Pp9QBmqoJ >JQeKnFByhiP9WbL47+hZ3trx2+vLjzHrZ7YLq5WN8kB5j1/v4HeZAR/HYPlmsB7X >8/mAtpfBEr5vSdRYPZlw7EiEiLP5dQhkcFIakWDLXurB+sDXPb1rchMG9g9/YPu3 >FR4oHM/o/66d03sFUwDMERQ5OYbRSY8qHLB8LDLMRstjEfGVQg/eG3RlVT/7yETh >gAMW2D+pFUHqe5QItxyOHyZ0FU0ak2qXO9BrjaQR4sHlQGO3tpPcRLalEhnrdluf >HBcKw9HQ85HY >-----END CERTIFICATE----- > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/bin/systemctl enable certmonger.service >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >2014-03-11T13:33:02Z DEBUG stderr=ln -s '/usr/lib/systemd/system/certmonger.service' '/etc/systemd/system/multi-user.target.wants/certmonger.service' > >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/bin/systemctl start messagebus.service >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/bin/systemctl is-active messagebus.service >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=active > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/bin/systemctl start certmonger.service >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/bin/systemctl is-active certmonger.service >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=active > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -L -d /etc/dirsrv/slapd-TESTRELM-TEST -n Server-Cert >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=Certificate: > Data: > Version: 3 (0x2) > Serial Number: 268369929 (0xfff0009) > Signature Algorithm: PKCS #1 SHA-256 With RSA Encryption > Issuer: "CN=Certificate Authority,O=TESTRELM.TEST" > Validity: > Not Before: Tue Mar 11 13:31:09 2014 > Not After : Fri Mar 11 13:31:09 2016 > Subject: "CN=rhel70-replica.testrelm.test,O=TESTRELM.TEST" > Subject Public Key Info: > Public Key Algorithm: PKCS #1 RSA Encryption > RSA Public Key: > Modulus: > c2:04:96:59:39:f0:85:d8:fc:01:b9:b6:da:e5:d9:36: > 7f:0e:fe:0e:b0:9b:ac:e1:ed:d2:6a:6f:35:cf:25:57: > 0f:23:f1:aa:05:8c:d4:a8:23:c6:4a:c9:6d:f6:f8:8b: > b7:94:84:b0:12:9c:da:86:41:53:bc:6c:a3:ba:44:77: > 66:90:4e:12:d7:3e:33:a8:dc:b0:b5:22:25:62:15:b4: > 5c:0e:14:22:29:62:de:4a:5e:42:87:eb:ba:61:cf:70: > c1:27:4b:1c:fe:5b:89:c8:e4:62:9b:ac:33:93:ee:08: > fa:c6:37:57:10:df:33:2f:5f:9c:db:5e:e5:bf:e4:d2: > 19:e3:26:10:11:db:4c:14:9c:40:b1:78:9c:8f:0f:66: > 54:62:92:61:cd:2d:b5:a7:79:b2:fe:32:89:27:ab:d2: > 7a:61:e8:b0:d8:6e:25:dc:83:cb:bc:8c:f6:2e:a2:f9: > 1b:23:f2:29:33:16:dd:fc:96:f2:b6:3e:0d:3d:69:2c: > e6:58:d0:f6:28:a2:c6:c8:d0:5a:bb:db:f2:d3:49:ba: > 0c:cb:33:19:4c:c7:77:8e:c5:71:0d:6f:5a:42:1f:63: > 7d:fb:b2:35:19:7c:2f:87:ce:7b:45:23:ea:55:bf:ee: > fc:ea:55:85:89:97:95:f3:b5:47:b3:59:b6:92:53:71 > Exponent: 65537 (0x10001) > Signed Extensions: > Name: Certificate Authority Key Identifier > Key ID: > 51:43:39:76:26:8a:9e:33:d9:5f:d7:db:a6:b3:69:e6: > 63:a1:86:05 > > Name: Authority Information Access > Method: PKIX Online Certificate Status Protocol > Location: > URI: "http://ipa-ca.testrelm.test/ca/ocsp" > > Name: Certificate Key Usage > Critical: True > Usages: Digital Signature > Non-Repudiation > Key Encipherment > Data Encipherment > > Name: Extended Key Usage > TLS Web Server Authentication Certificate > TLS Web Client Authentication Certificate > > Name: CRL Distribution Points > Distribution point: > URI: "http://ipa-ca.testrelm.test/ipa/crl/MasterCRL.bin" > CRL issuer: > Directory Name: "CN=Certificate Authority,O=ipaca" > > Name: Certificate Subject Key ID > Data: > 5a:f2:26:6a:fd:8b:a0:8f:6a:8f:1b:91:2e:97:dc:2b: > 02:49:c1:7e > > Signature Algorithm: PKCS #1 SHA-256 With RSA Encryption > Signature: > 0a:54:c6:45:b3:b3:88:eb:b7:e6:0e:1a:dc:37:01:b3: > 7c:c2:59:10:9b:4a:f0:c5:95:af:09:e5:56:33:55:5a: > 30:0c:d1:bc:9e:2c:d2:a7:e7:7f:23:88:a7:74:d8:ed: > 0f:a7:d4:01:9a:aa:09:25:07:8a:9c:50:72:86:23:fd: > 59:b2:f8:ef:e8:59:de:da:f1:db:eb:cb:8f:31:eb:67: > b6:0b:ab:95:8d:f2:40:79:8f:5f:ef:e0:77:99:01:1f: > c7:60:f9:66:b0:1e:d7:f3:f9:80:b6:97:c1:12:be:6f: > 49:d4:58:3d:99:70:ec:48:84:88:b3:f9:75:08:64:70: > 52:1a:91:60:cb:5e:ea:c1:fa:c0:d7:3d:bd:6b:72:13: > 06:f6:0f:7f:60:fb:b7:15:1e:28:1c:cf:e8:ff:ae:9d: > d3:7b:05:53:00:cc:11:14:39:39:86:d1:49:8f:2a:1c: > b0:7c:2c:32:cc:46:cb:63:11:f1:95:42:0f:de:1b:74: > 65:55:3f:fb:c8:44:e1:80:03:16:d8:3f:a9:15:41:ea: > 7b:94:08:b7:1c:8e:1f:26:74:15:4d:1a:93:6a:97:3b: > d0:6b:8d:a4:11:e2:c1:e5:40:63:b7:b6:93:dc:44:b6: > a5:12:19:eb:76:5b:9f:1c:17:0a:c3:d1:d0:f3:91:d8 > Fingerprint (MD5): > FB:95:C4:29:B4:AC:4B:A6:9A:71:16:84:6A:90:10:F7 > Fingerprint (SHA1): > FB:A9:2A:D6:8E:DA:F8:47:80:95:2A:BF:40:7B:6D:1F:29:C5:11:3B > > Certificate Trust Flags: > SSL Flags: > User > Email Flags: > User > Object Signing Flags: > User > > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/ipa-getcert start-tracking -d /etc/dirsrv/slapd-TESTRELM-TEST -n Server-Cert -p /etc/dirsrv/slapd-TESTRELM-TEST/pwdfile.txt -C /usr/lib64/ipa/certmonger/restart_dirsrv TESTRELM-TEST >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=New tracking request "20140311133302" added. > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/bin/systemctl stop certmonger.service >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout= >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:02Z DEBUG Starting external process >2014-03-11T13:33:02Z DEBUG args=/usr/bin/certutil -d /etc/dirsrv/slapd-TESTRELM-TEST/ -L -n Server-Cert -a >2014-03-11T13:33:02Z DEBUG Process finished, return code=0 >2014-03-11T13:33:02Z DEBUG stdout=-----BEGIN CERTIFICATE----- >MIIEJTCCAw2gAwIBAgIED/8ACTANBgkqhkiG9w0BAQsFADA4MRYwFAYDVQQKEw1U >RVNUUkVMTS5URVNUMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcN >MTQwMzExMTMzMTA5WhcNMTYwMzExMTMzMTA5WjA/MRYwFAYDVQQKEw1URVNUUkVM >TS5URVNUMSUwIwYDVQQDExxyaGVsNzAtcmVwbGljYS50ZXN0cmVsbS50ZXN0MIIB >IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwgSWWTnwhdj8Abm22uXZNn8O >/g6wm6zh7dJqbzXPJVcPI/GqBYzUqCPGSslt9viLt5SEsBKc2oZBU7xso7pEd2aQ >ThLXPjOo3LC1IiViFbRcDhQiKWLeSl5Ch+u6Yc9wwSdLHP5bicjkYpusM5PuCPrG >N1cQ3zMvX5zbXuW/5NIZ4yYQEdtMFJxAsXicjw9mVGKSYc0ttad5sv4yiSer0nph >6LDYbiXcg8u8jPYuovkbI/IpMxbd/Jbytj4NPWks5ljQ9iiixsjQWrvb8tNJugzL >MxlMx3eOxXENb1pCH2N9+7I1GXwvh857RSPqVb/u/OpVhYmXlfO1R7NZtpJTcQID >AQABo4IBLjCCASowHwYDVR0jBBgwFoAUUUM5diaKnjPZX9fbprNp5mOhhgUwPwYI >KwYBBQUHAQEEMzAxMC8GCCsGAQUFBzABhiNodHRwOi8vaXBhLWNhLnRlc3RyZWxt >LnRlc3QvY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBPAwHQYDVR0lBBYwFAYIKwYBBQUH >AwEGCCsGAQUFBwMCMHgGA1UdHwRxMG8wbaA1oDOGMWh0dHA6Ly9pcGEtY2EudGVz >dHJlbG0udGVzdC9pcGEvY3JsL01hc3RlckNSTC5iaW6iNKQyMDAxDjAMBgNVBAoT >BWlwYWNhMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHQYDVR0OBBYE >FFryJmr9i6CPao8bkS6X3CsCScF+MA0GCSqGSIb3DQEBCwUAA4IBAQAKVMZFs7OI >67fmDhrcNwGzfMJZEJtK8MWVrwnlVjNVWjAM0byeLNKn538jiKd02O0Pp9QBmqoJ >JQeKnFByhiP9WbL47+hZ3trx2+vLjzHrZ7YLq5WN8kB5j1/v4HeZAR/HYPlmsB7X >8/mAtpfBEr5vSdRYPZlw7EiEiLP5dQhkcFIakWDLXurB+sDXPb1rchMG9g9/YPu3 >FR4oHM/o/66d03sFUwDMERQ5OYbRSY8qHLB8LDLMRstjEfGVQg/eG3RlVT/7yETh >gAMW2D+pFUHqe5QItxyOHyZ0FU0ak2qXO9BrjaQR4sHlQGO3tpPcRLalEhnrdluf >HBcKw9HQ85HY >-----END CERTIFICATE----- > >2014-03-11T13:33:02Z DEBUG stderr= >2014-03-11T13:33:14Z DEBUG Starting external process >2014-03-11T13:33:14Z DEBUG args=/bin/systemctl start certmonger.service >2014-03-11T13:33:14Z DEBUG Process finished, return code=0 >2014-03-11T13:33:14Z DEBUG stdout= >2014-03-11T13:33:14Z DEBUG stderr= >2014-03-11T13:33:14Z DEBUG Starting external process >2014-03-11T13:33:14Z DEBUG args=/bin/systemctl is-active certmonger.service >2014-03-11T13:33:14Z DEBUG Process finished, return code=0 >2014-03-11T13:33:14Z DEBUG stdout=active > >2014-03-11T13:33:14Z DEBUG stderr= >2014-03-11T13:33:14Z DEBUG flushing ldap://rhel70-replica.testrelm.test:389 from SchemaCache >2014-03-11T13:33:14Z DEBUG retrieving schema for SchemaCache url=ldap://rhel70-replica.testrelm.test:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x2c82560> >2014-03-11T13:33:15Z DEBUG duration: 12 seconds >2014-03-11T13:33:15Z DEBUG [18/34]: configuring certmap.conf >2014-03-11T13:33:15Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' >2014-03-11T13:33:15Z DEBUG duration: 0 seconds >2014-03-11T13:33:15Z DEBUG [19/34]: configure autobind for root >2014-03-11T13:33:15Z DEBUG Starting external process >2014-03-11T13:33:15Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/root-autobind.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmp90hnnr >2014-03-11T13:33:15Z DEBUG Process finished, return code=0 >2014-03-11T13:33:15Z DEBUG stdout=add objectClass: > extensibleObject > top >add cn: > root-autobind >add uidNumber: > 0 >add gidNumber: > 0 >adding new entry "cn=root-autobind,cn=config" >modify complete > >replace nsslapd-ldapiautobind: > on >modifying entry "cn=config" >modify complete > >replace nsslapd-ldapimaptoentries: > on >modifying entry "cn=config" >modify complete > > >2014-03-11T13:33:15Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:15Z DEBUG duration: 0 seconds >2014-03-11T13:33:15Z DEBUG [20/34]: configure new location for managed entries >2014-03-11T13:33:15Z DEBUG Starting external process >2014-03-11T13:33:15Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpwbOuE7 -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmph45vaG >2014-03-11T13:33:15Z DEBUG Process finished, return code=0 >2014-03-11T13:33:15Z DEBUG stdout=add nsslapd-pluginConfigArea: > cn=Definitions,cn=Managed Entries,cn=etc,dc=testrelm,dc=test >modifying entry "cn=Managed Entries,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:15Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:15Z DEBUG duration: 0 seconds >2014-03-11T13:33:15Z DEBUG [21/34]: configure dirsrv ccache >2014-03-11T13:33:15Z DEBUG Backing up system configuration file '/etc/sysconfig/dirsrv' >2014-03-11T13:33:15Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' >2014-03-11T13:33:15Z DEBUG Starting external process >2014-03-11T13:33:15Z DEBUG args=/usr/sbin/selinuxenabled >2014-03-11T13:33:15Z DEBUG Process finished, return code=0 >2014-03-11T13:33:15Z DEBUG stdout= >2014-03-11T13:33:15Z DEBUG stderr= >2014-03-11T13:33:15Z DEBUG Starting external process >2014-03-11T13:33:15Z DEBUG args=/usr/sbin/restorecon /etc/sysconfig/dirsrv >2014-03-11T13:33:15Z DEBUG Process finished, return code=0 >2014-03-11T13:33:15Z DEBUG stdout= >2014-03-11T13:33:15Z DEBUG stderr= >2014-03-11T13:33:15Z DEBUG duration: 0 seconds >2014-03-11T13:33:15Z DEBUG [22/34]: enable SASL mapping fallback >2014-03-11T13:33:15Z DEBUG Starting external process >2014-03-11T13:33:15Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpv2VTf6 -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpz7Qj1V >2014-03-11T13:33:15Z DEBUG Process finished, return code=0 >2014-03-11T13:33:15Z DEBUG stdout=replace nsslapd-sasl-mapping-fallback: > on >modifying entry "cn=config" >modify complete > > >2014-03-11T13:33:15Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:15Z DEBUG duration: 0 seconds >2014-03-11T13:33:15Z DEBUG [23/34]: restarting directory server >2014-03-11T13:33:15Z DEBUG Starting external process >2014-03-11T13:33:15Z DEBUG args=/bin/systemctl --system daemon-reload >2014-03-11T13:33:15Z DEBUG Process finished, return code=0 >2014-03-11T13:33:15Z DEBUG stdout= >2014-03-11T13:33:15Z DEBUG stderr= >2014-03-11T13:33:15Z DEBUG Starting external process >2014-03-11T13:33:15Z DEBUG args=/bin/systemctl restart dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:16Z DEBUG Process finished, return code=0 >2014-03-11T13:33:16Z DEBUG stdout= >2014-03-11T13:33:16Z DEBUG stderr= >2014-03-11T13:33:16Z DEBUG Starting external process >2014-03-11T13:33:16Z DEBUG args=/bin/systemctl is-active dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:16Z DEBUG Process finished, return code=0 >2014-03-11T13:33:16Z DEBUG stdout=active > >2014-03-11T13:33:16Z DEBUG stderr= >2014-03-11T13:33:16Z DEBUG wait_for_open_ports: localhost [389] timeout 300 >2014-03-11T13:33:17Z DEBUG Starting external process >2014-03-11T13:33:17Z DEBUG args=/bin/systemctl is-active dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:17Z DEBUG Process finished, return code=0 >2014-03-11T13:33:17Z DEBUG stdout=active > >2014-03-11T13:33:17Z DEBUG stderr= >2014-03-11T13:33:17Z DEBUG duration: 2 seconds >2014-03-11T13:33:17Z DEBUG [24/34]: setting up initial replication >2014-03-11T13:33:17Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-TESTRELM-TEST.socket from SchemaCache >2014-03-11T13:33:17Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-TESTRELM-TEST.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x2dccd88> >2014-03-11T13:33:17Z DEBUG Starting external process >2014-03-11T13:33:17Z DEBUG args=/bin/systemctl --system daemon-reload >2014-03-11T13:33:17Z DEBUG Process finished, return code=0 >2014-03-11T13:33:17Z DEBUG stdout= >2014-03-11T13:33:17Z DEBUG stderr= >2014-03-11T13:33:17Z DEBUG Starting external process >2014-03-11T13:33:17Z DEBUG args=/bin/systemctl restart dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:19Z DEBUG Process finished, return code=0 >2014-03-11T13:33:19Z DEBUG stdout= >2014-03-11T13:33:19Z DEBUG stderr= >2014-03-11T13:33:19Z DEBUG Starting external process >2014-03-11T13:33:19Z DEBUG args=/bin/systemctl is-active dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:19Z DEBUG Process finished, return code=0 >2014-03-11T13:33:19Z DEBUG stdout=active > >2014-03-11T13:33:19Z DEBUG stderr= >2014-03-11T13:33:19Z DEBUG wait_for_open_ports: localhost [389] timeout 300 >2014-03-11T13:33:22Z DEBUG flushing ldap://hp-dc5800-01.testrelm.test:389 from SchemaCache >2014-03-11T13:33:22Z DEBUG retrieving schema for SchemaCache url=ldap://hp-dc5800-01.testrelm.test:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x47ce488> >2014-03-11T13:33:24Z DEBUG flushing ldaps://rhel70-replica.testrelm.test:636 from SchemaCache >2014-03-11T13:33:24Z DEBUG retrieving schema for SchemaCache url=ldaps://rhel70-replica.testrelm.test:636 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x42f6200> >2014-03-11T13:33:55Z DEBUG duration: 37 seconds >2014-03-11T13:33:55Z DEBUG [25/34]: updating schema >2014-03-11T13:33:55Z DEBUG Starting external process >2014-03-11T13:33:55Z DEBUG args=/usr/bin/ldapmodify -v -f /usr/share/ipa/schema-update.ldif -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpFK5m6s >2014-03-11T13:33:55Z DEBUG Process finished, return code=0 >2014-03-11T13:33:55Z DEBUG stdout=add objectClasses: > ( 2.16.840.1.113730.3.2.41 NAME 'nsslapdPlugin' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsslapd-pluginPath $ nsslapd-pluginInitFunc $ nsslapd-pluginType $ nsslapd-pluginId $ nsslapd-pluginVersion $ nsslapd-pluginVendor $ nsslapd-pluginDescription $ nsslapd-pluginEnabled ) MAY ( nsslapd-pluginConfigArea $ nsslapd-plugin-depends-on-type ) X-ORIGIN 'Netscape Directory Server' ) > ( 2.16.840.1.113730.3.2.317 NAME 'nsSaslMapping' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsSaslMapRegexString $ nsSaslMapBaseDNTemplate $ nsSaslMapFilterTemplate ) MAY ( nsSaslMapPriority ) X-ORIGIN 'Netscape Directory Server' ) >modifying entry "cn=schema" >modify complete > > >2014-03-11T13:33:55Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:55Z DEBUG duration: 0 seconds >2014-03-11T13:33:55Z DEBUG [26/34]: setting Auto Member configuration >2014-03-11T13:33:55Z DEBUG Starting external process >2014-03-11T13:33:55Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpDZyErX -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpVFfMcC >2014-03-11T13:33:55Z DEBUG Process finished, return code=0 >2014-03-11T13:33:55Z DEBUG stdout=add nsslapd-pluginConfigArea: > cn=automember,cn=etc,dc=testrelm,dc=test >modifying entry "cn=Auto Membership Plugin,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:55Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:55Z DEBUG duration: 0 seconds >2014-03-11T13:33:55Z DEBUG [27/34]: enabling S4U2Proxy delegation >2014-03-11T13:33:55Z DEBUG Starting external process >2014-03-11T13:33:55Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpPb2vvf -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpXOSxj6 >2014-03-11T13:33:55Z DEBUG Process finished, return code=0 >2014-03-11T13:33:55Z DEBUG stdout=add memberPrincipal: > HTTP/rhel70-replica.testrelm.test@TESTRELM.TEST >modifying entry "cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=testrelm,dc=test" >modify complete > >add memberPrincipal: > ldap/rhel70-replica.testrelm.test@TESTRELM.TEST >modifying entry "cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=testrelm,dc=test" >modify complete > > >2014-03-11T13:33:55Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:55Z DEBUG duration: 0 seconds >2014-03-11T13:33:55Z DEBUG [28/34]: initializing group membership >2014-03-11T13:33:55Z DEBUG duration: 0 seconds >2014-03-11T13:33:55Z DEBUG [29/34]: adding master entry >2014-03-11T13:33:55Z DEBUG Starting external process >2014-03-11T13:33:55Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpQwtLAf -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmp1GXaqt >2014-03-11T13:33:55Z DEBUG Process finished, return code=0 >2014-03-11T13:33:55Z DEBUG stdout=add objectclass: > top > nsContainer >add cn: > rhel70-replica.testrelm.test >adding new entry "cn=rhel70-replica.testrelm.test,cn=masters,cn=ipa,cn=etc,dc=testrelm,dc=test" >modify complete > > >2014-03-11T13:33:55Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:55Z DEBUG duration: 0 seconds >2014-03-11T13:33:55Z DEBUG [30/34]: configuring Posix uid/gid generation >2014-03-11T13:33:55Z DEBUG Starting external process >2014-03-11T13:33:55Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpjk86vj -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpKB7tLd >2014-03-11T13:33:55Z DEBUG Process finished, return code=0 >2014-03-11T13:33:55Z DEBUG stdout=add objectclass: > top > extensibleObject >add cn: > Posix IDs >add dnaType: > uidNumber > gidNumber >add dnaNextValue: > 1101 >add dnaMaxValue: > 1100 >add dnaMagicRegen: > -1 >add dnaFilter: > (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) >add dnaScope: > dc=testrelm,dc=test >add dnaThreshold: > 500 >add dnaSharedCfgDN: > cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=testrelm,dc=test >adding new entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" >modify complete > > >2014-03-11T13:33:55Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:55Z DEBUG duration: 0 seconds >2014-03-11T13:33:55Z DEBUG [31/34]: adding replication acis >2014-03-11T13:33:55Z DEBUG Starting external process >2014-03-11T13:33:55Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmp4npExK -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpVUUuhR >2014-03-11T13:33:55Z DEBUG Process finished, return code=0 >2014-03-11T13:33:55Z DEBUG stdout=add aci: > (targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=testrelm,dc=test";) >modifying entry "cn=config" >modify complete > >add aci: > (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=testrelm,dc=test";) >modifying entry "cn="dc=testrelm,dc=test",cn=mapping tree,cn=config" >modify complete > >add aci: > (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=testrelm,dc=test";) >modifying entry "cn="dc=testrelm,dc=test",cn=mapping tree,cn=config" >modify complete > >add aci: > (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=testrelm,dc=test";) >modifying entry "cn="dc=testrelm,dc=test",cn=mapping tree,cn=config" >modify complete > >add aci: > (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=testrelm,dc=test";) >modifying entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" >modify complete > >add aci: > (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=testrelm,dc=test";) >modifying entry "cn=userRoot,cn=ldbm database,cn=plugins,cn=config" >modify complete > >add aci: > (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=testrelm,dc=test";) >modifying entry "cn=tasks,cn=config" >modify complete > > >2014-03-11T13:33:55Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:55Z DEBUG duration: 0 seconds >2014-03-11T13:33:55Z DEBUG [32/34]: enabling compatibility plugin >2014-03-11T13:33:56Z INFO Parsing update file '/usr/share/ipa/schema_compat.uldif' >2014-03-11T13:33:56Z DEBUG flushing ldap://rhel70-replica.testrelm.test:389 from SchemaCache >2014-03-11T13:33:56Z DEBUG retrieving schema for SchemaCache url=ldap://rhel70-replica.testrelm.test:389 conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x4ce03b0> >2014-03-11T13:33:56Z INFO New entry: cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Initial value >2014-03-11T13:33:56Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG nsslapd-pluginbetxn: >2014-03-11T13:33:56Z DEBUG on >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG Schema Compatibility >2014-03-11T13:33:56Z DEBUG objectclass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG nsSlapdPlugin >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG nsslapd-plugindescription: >2014-03-11T13:33:56Z DEBUG Schema Compatibility Plugin >2014-03-11T13:33:56Z DEBUG nsslapd-pluginenabled: >2014-03-11T13:33:56Z DEBUG on >2014-03-11T13:33:56Z DEBUG nsslapd-pluginid: >2014-03-11T13:33:56Z DEBUG schema-compat-plugin >2014-03-11T13:33:56Z DEBUG nsslapd-pluginversion: >2014-03-11T13:33:56Z DEBUG 0.8 >2014-03-11T13:33:56Z DEBUG nsslapd-pluginpath: >2014-03-11T13:33:56Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so >2014-03-11T13:33:56Z DEBUG nsslapd-pluginvendor: >2014-03-11T13:33:56Z DEBUG redhat.com >2014-03-11T13:33:56Z DEBUG nsslapd-plugintype: >2014-03-11T13:33:56Z DEBUG object >2014-03-11T13:33:56Z DEBUG nsslapd-plugininitfunc: >2014-03-11T13:33:56Z DEBUG schema_compat_plugin_init >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Final value after applying updates >2014-03-11T13:33:56Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG nsslapd-pluginbetxn: >2014-03-11T13:33:56Z DEBUG on >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG Schema Compatibility >2014-03-11T13:33:56Z DEBUG objectclass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG nsSlapdPlugin >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG nsslapd-plugindescription: >2014-03-11T13:33:56Z DEBUG Schema Compatibility Plugin >2014-03-11T13:33:56Z DEBUG nsslapd-pluginenabled: >2014-03-11T13:33:56Z DEBUG on >2014-03-11T13:33:56Z DEBUG nsslapd-pluginid: >2014-03-11T13:33:56Z DEBUG schema-compat-plugin >2014-03-11T13:33:56Z DEBUG nsslapd-pluginversion: >2014-03-11T13:33:56Z DEBUG 0.8 >2014-03-11T13:33:56Z DEBUG nsslapd-pluginpath: >2014-03-11T13:33:56Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so >2014-03-11T13:33:56Z DEBUG nsslapd-pluginvendor: >2014-03-11T13:33:56Z DEBUG redhat.com >2014-03-11T13:33:56Z DEBUG nsslapd-plugintype: >2014-03-11T13:33:56Z DEBUG object >2014-03-11T13:33:56Z DEBUG nsslapd-plugininitfunc: >2014-03-11T13:33:56Z DEBUG schema_compat_plugin_init >2014-03-11T13:33:56Z INFO Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Initial value >2014-03-11T13:33:56Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG directoryServerFeature >2014-03-11T13:33:56Z DEBUG aci: >2014-03-11T13:33:56Z DEBUG (targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";) >2014-03-11T13:33:56Z DEBUG oid: >2014-03-11T13:33:56Z DEBUG 2.16.840.1.113730.3.4.9 >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG VLV Request Control >2014-03-11T13:33:56Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value [u'(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'] >2014-03-11T13:33:56Z DEBUG only: updated value [u'(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Final value after applying updates >2014-03-11T13:33:56Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG directoryServerFeature >2014-03-11T13:33:56Z DEBUG aci: >2014-03-11T13:33:56Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) >2014-03-11T13:33:56Z DEBUG oid: >2014-03-11T13:33:56Z DEBUG 2.16.840.1.113730.3.4.9 >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG VLV Request Control >2014-03-11T13:33:56Z DEBUG [(0, u'aci', ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )']), (1, u'aci', [u'(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'])] >2014-03-11T13:33:56Z DEBUG Live 1, updated 1 >2014-03-11T13:33:56Z INFO Done >2014-03-11T13:33:56Z INFO New entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Initial value >2014-03-11T13:33:56Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG schema-compat-entry-attribute: >2014-03-11T13:33:56Z DEBUG objectclass=posixAccount >2014-03-11T13:33:56Z DEBUG gecos=%{cn} >2014-03-11T13:33:56Z DEBUG cn=%{cn} >2014-03-11T13:33:56Z DEBUG uidNumber=%{uidNumber} >2014-03-11T13:33:56Z DEBUG gidNumber=%{gidNumber} >2014-03-11T13:33:56Z DEBUG loginShell=%{loginShell} >2014-03-11T13:33:56Z DEBUG homeDirectory=%{homeDirectory} >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG users >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG schema-compat-search-filter: >2014-03-11T13:33:56Z DEBUG objectclass=posixAccount >2014-03-11T13:33:56Z DEBUG schema-compat-container-rdn: >2014-03-11T13:33:56Z DEBUG cn=users >2014-03-11T13:33:56Z DEBUG schema-compat-entry-rdn: >2014-03-11T13:33:56Z DEBUG uid=%{uid} >2014-03-11T13:33:56Z DEBUG schema-compat-search-base: >2014-03-11T13:33:56Z DEBUG cn=users, cn=accounts, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG schema-compat-container-group: >2014-03-11T13:33:56Z DEBUG cn=compat, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Final value after applying updates >2014-03-11T13:33:56Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG schema-compat-entry-attribute: >2014-03-11T13:33:56Z DEBUG objectclass=posixAccount >2014-03-11T13:33:56Z DEBUG gecos=%{cn} >2014-03-11T13:33:56Z DEBUG cn=%{cn} >2014-03-11T13:33:56Z DEBUG uidNumber=%{uidNumber} >2014-03-11T13:33:56Z DEBUG gidNumber=%{gidNumber} >2014-03-11T13:33:56Z DEBUG loginShell=%{loginShell} >2014-03-11T13:33:56Z DEBUG homeDirectory=%{homeDirectory} >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG users >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG schema-compat-search-filter: >2014-03-11T13:33:56Z DEBUG objectclass=posixAccount >2014-03-11T13:33:56Z DEBUG schema-compat-container-rdn: >2014-03-11T13:33:56Z DEBUG cn=users >2014-03-11T13:33:56Z DEBUG schema-compat-entry-rdn: >2014-03-11T13:33:56Z DEBUG uid=%{uid} >2014-03-11T13:33:56Z DEBUG schema-compat-search-base: >2014-03-11T13:33:56Z DEBUG cn=users, cn=accounts, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG schema-compat-container-group: >2014-03-11T13:33:56Z DEBUG cn=compat, dc=testrelm,dc=test >2014-03-11T13:33:56Z INFO New entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Initial value >2014-03-11T13:33:56Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG add: 'top' to objectClass, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'top'] >2014-03-11T13:33:56Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'top', u'extensibleObject'] >2014-03-11T13:33:56Z DEBUG add: 'sudoers' to cn, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'sudoers'] >2014-03-11T13:33:56Z DEBUG add: 'ou=SUDOers, dc=testrelm,dc=test' to schema-compat-container-group, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'ou=SUDOers, dc=testrelm,dc=test'] >2014-03-11T13:33:56Z DEBUG add: 'cn=sudorules, cn=sudo, dc=testrelm,dc=test' to schema-compat-search-base, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'cn=sudorules, cn=sudo, dc=testrelm,dc=test'] >2014-03-11T13:33:56Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] >2014-03-11T13:33:56Z DEBUG add: '%ifeq("ipaEnabledFlag"' to schema-compat-entry-rdn, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'%ifeq("ipaEnabledFlag"'] >2014-03-11T13:33:56Z DEBUG add: 'FALSE' to schema-compat-entry-rdn, current value [u'%ifeq("ipaEnabledFlag"'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'%ifeq("ipaEnabledFlag"', u'FALSE'] >2014-03-11T13:33:56Z DEBUG add: 'DISABLED' to schema-compat-entry-rdn, current value [u'%ifeq("ipaEnabledFlag"', u'FALSE'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'%ifeq("ipaEnabledFlag"', u'FALSE', u'DISABLED'] >2014-03-11T13:33:56Z DEBUG add: 'cn=%{cn})' to schema-compat-entry-rdn, current value [u'%ifeq("ipaEnabledFlag"', u'FALSE', u'DISABLED'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'%ifeq("ipaEnabledFlag"', u'FALSE', u'DISABLED', u'cn=%{cn})'] >2014-03-11T13:33:56Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole'] >2014-03-11T13:33:56Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}'] >2014-03-11T13:33:56Z DEBUG add: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}', u'sudoRunAsUser=%deref("ipaSudoRunAs","uid")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}', u'sudoRunAsUser=%deref("ipaSudoRunAs","uid")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}', u'sudoRunAsUser=%deref("ipaSudoRunAs","uid")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}', u'sudoRunAsUser=%deref("ipaSudoRunAs","uid")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}', u'sudoRunAsUser=%deref("ipaSudoRunAs","uid")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}'] >2014-03-11T13:33:56Z DEBUG add: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}', u'sudoRunAsUser=%deref("ipaSudoRunAs","uid")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}', u'sudoRunAsUser=%deref("ipaSudoRunAs","uid")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}', u'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")'] >2014-03-11T13:33:56Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}', u'sudoRunAsUser=%deref("ipaSudoRunAs","uid")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}', u'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%{ipaSudoRunAsExtUser}', u'sudoRunAsUser=%deref("ipaSudoRunAs","uid")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}', u'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")', u'sudoOption=%{ipaSudoOpt}'] >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Final value after applying updates >2014-03-11T13:33:56Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG schema-compat-entry-attribute: >2014-03-11T13:33:56Z DEBUG objectclass=sudoRole >2014-03-11T13:33:56Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") >2014-03-11T13:33:56Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") >2014-03-11T13:33:56Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") >2014-03-11T13:33:56Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") >2014-03-11T13:33:56Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") >2014-03-11T13:33:56Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") >2014-03-11T13:33:56Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") >2014-03-11T13:33:56Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") >2014-03-11T13:33:56Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") >2014-03-11T13:33:56Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") >2014-03-11T13:33:56Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") >2014-03-11T13:33:56Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") >2014-03-11T13:33:56Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") >2014-03-11T13:33:56Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") >2014-03-11T13:33:56Z DEBUG sudoRunAsUser=%{ipaSudoRunAsExtUser} >2014-03-11T13:33:56Z DEBUG sudoRunAsUser=%deref("ipaSudoRunAs","uid") >2014-03-11T13:33:56Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") >2014-03-11T13:33:56Z DEBUG sudoRunAsGroup=%{ipaSudoRunAsExtGroup} >2014-03-11T13:33:56Z DEBUG sudoRunAsGroup=%deref("ipaSudoRunAs","cn") >2014-03-11T13:33:56Z DEBUG sudoOption=%{ipaSudoOpt} >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG sudoers >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG schema-compat-search-filter: >2014-03-11T13:33:56Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) >2014-03-11T13:33:56Z DEBUG schema-compat-entry-rdn: >2014-03-11T13:33:56Z DEBUG %ifeq("ipaEnabledFlag" >2014-03-11T13:33:56Z DEBUG FALSE >2014-03-11T13:33:56Z DEBUG DISABLED >2014-03-11T13:33:56Z DEBUG cn=%{cn}) >2014-03-11T13:33:56Z DEBUG schema-compat-search-base: >2014-03-11T13:33:56Z DEBUG cn=sudorules, cn=sudo, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG schema-compat-container-group: >2014-03-11T13:33:56Z DEBUG ou=SUDOers, dc=testrelm,dc=test >2014-03-11T13:33:56Z INFO New entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Initial value >2014-03-11T13:33:56Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG schema-compat-entry-attribute: >2014-03-11T13:33:56Z DEBUG objectclass=device >2014-03-11T13:33:56Z DEBUG objectclass=ieee802Device >2014-03-11T13:33:56Z DEBUG cn=%{fqdn} >2014-03-11T13:33:56Z DEBUG macAddress=%{macAddress} >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG computers >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG schema-compat-search-filter: >2014-03-11T13:33:56Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) >2014-03-11T13:33:56Z DEBUG schema-compat-container-rdn: >2014-03-11T13:33:56Z DEBUG cn=computers >2014-03-11T13:33:56Z DEBUG schema-compat-entry-rdn: >2014-03-11T13:33:56Z DEBUG cn=%first("%{fqdn}") >2014-03-11T13:33:56Z DEBUG schema-compat-search-base: >2014-03-11T13:33:56Z DEBUG cn=computers, cn=accounts, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG schema-compat-container-group: >2014-03-11T13:33:56Z DEBUG cn=compat, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Final value after applying updates >2014-03-11T13:33:56Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG schema-compat-entry-attribute: >2014-03-11T13:33:56Z DEBUG objectclass=device >2014-03-11T13:33:56Z DEBUG objectclass=ieee802Device >2014-03-11T13:33:56Z DEBUG cn=%{fqdn} >2014-03-11T13:33:56Z DEBUG macAddress=%{macAddress} >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG computers >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG schema-compat-search-filter: >2014-03-11T13:33:56Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) >2014-03-11T13:33:56Z DEBUG schema-compat-container-rdn: >2014-03-11T13:33:56Z DEBUG cn=computers >2014-03-11T13:33:56Z DEBUG schema-compat-entry-rdn: >2014-03-11T13:33:56Z DEBUG cn=%first("%{fqdn}") >2014-03-11T13:33:56Z DEBUG schema-compat-search-base: >2014-03-11T13:33:56Z DEBUG cn=computers, cn=accounts, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG schema-compat-container-group: >2014-03-11T13:33:56Z DEBUG cn=compat, dc=testrelm,dc=test >2014-03-11T13:33:56Z INFO New entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Initial value >2014-03-11T13:33:56Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG add: 'top' to objectClass, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'top'] >2014-03-11T13:33:56Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'top', u'extensibleObject'] >2014-03-11T13:33:56Z DEBUG add: 'ng' to cn, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'ng'] >2014-03-11T13:33:56Z DEBUG add: 'cn=compat, dc=testrelm,dc=test' to schema-compat-container-group, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'cn=compat, dc=testrelm,dc=test'] >2014-03-11T13:33:56Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'cn=ng'] >2014-03-11T13:33:56Z DEBUG add: 'yes' to schema-compat-check-access, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'yes'] >2014-03-11T13:33:56Z DEBUG add: 'cn=ng, cn=alt, dc=testrelm,dc=test' to schema-compat-search-base, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'cn=ng, cn=alt, dc=testrelm,dc=test'] >2014-03-11T13:33:56Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'(objectclass=ipaNisNetgroup)'] >2014-03-11T13:33:56Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'cn=%{cn}'] >2014-03-11T13:33:56Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value [] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=nisNetgroup'] >2014-03-11T13:33:56Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value [u'objectclass=nisNetgroup'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")'] >2014-03-11T13:33:56Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")'] >2014-03-11T13:33:56Z DEBUG add: updated value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'] >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Final value after applying updates >2014-03-11T13:33:56Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG schema-compat-entry-attribute: >2014-03-11T13:33:56Z DEBUG objectclass=nisNetgroup >2014-03-11T13:33:56Z DEBUG memberNisNetgroup=%deref_r("member","cn") >2014-03-11T13:33:56Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) >2014-03-11T13:33:56Z DEBUG schema-compat-check-access: >2014-03-11T13:33:56Z DEBUG yes >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG ng >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG schema-compat-search-filter: >2014-03-11T13:33:56Z DEBUG (objectclass=ipaNisNetgroup) >2014-03-11T13:33:56Z DEBUG schema-compat-container-rdn: >2014-03-11T13:33:56Z DEBUG cn=ng >2014-03-11T13:33:56Z DEBUG schema-compat-entry-rdn: >2014-03-11T13:33:56Z DEBUG cn=%{cn} >2014-03-11T13:33:56Z DEBUG schema-compat-search-base: >2014-03-11T13:33:56Z DEBUG cn=ng, cn=alt, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG schema-compat-container-group: >2014-03-11T13:33:56Z DEBUG cn=compat, dc=testrelm,dc=test >2014-03-11T13:33:56Z INFO New entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Initial value >2014-03-11T13:33:56Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG schema-compat-entry-attribute: >2014-03-11T13:33:56Z DEBUG objectclass=posixGroup >2014-03-11T13:33:56Z DEBUG gidNumber=%{gidNumber} >2014-03-11T13:33:56Z DEBUG memberUid=%{memberUid} >2014-03-11T13:33:56Z DEBUG memberUid=%deref_r("member","uid") >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG groups >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG schema-compat-search-filter: >2014-03-11T13:33:56Z DEBUG objectclass=posixGroup >2014-03-11T13:33:56Z DEBUG schema-compat-container-rdn: >2014-03-11T13:33:56Z DEBUG cn=groups >2014-03-11T13:33:56Z DEBUG schema-compat-entry-rdn: >2014-03-11T13:33:56Z DEBUG cn=%{cn} >2014-03-11T13:33:56Z DEBUG schema-compat-search-base: >2014-03-11T13:33:56Z DEBUG cn=groups, cn=accounts, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG schema-compat-container-group: >2014-03-11T13:33:56Z DEBUG cn=compat, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG --------------------------------------------- >2014-03-11T13:33:56Z DEBUG Final value after applying updates >2014-03-11T13:33:56Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config >2014-03-11T13:33:56Z DEBUG schema-compat-entry-attribute: >2014-03-11T13:33:56Z DEBUG objectclass=posixGroup >2014-03-11T13:33:56Z DEBUG gidNumber=%{gidNumber} >2014-03-11T13:33:56Z DEBUG memberUid=%{memberUid} >2014-03-11T13:33:56Z DEBUG memberUid=%deref_r("member","uid") >2014-03-11T13:33:56Z DEBUG cn: >2014-03-11T13:33:56Z DEBUG groups >2014-03-11T13:33:56Z DEBUG objectClass: >2014-03-11T13:33:56Z DEBUG top >2014-03-11T13:33:56Z DEBUG extensibleObject >2014-03-11T13:33:56Z DEBUG schema-compat-search-filter: >2014-03-11T13:33:56Z DEBUG objectclass=posixGroup >2014-03-11T13:33:56Z DEBUG schema-compat-container-rdn: >2014-03-11T13:33:56Z DEBUG cn=groups >2014-03-11T13:33:56Z DEBUG schema-compat-entry-rdn: >2014-03-11T13:33:56Z DEBUG cn=%{cn} >2014-03-11T13:33:56Z DEBUG schema-compat-search-base: >2014-03-11T13:33:56Z DEBUG cn=groups, cn=accounts, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG schema-compat-container-group: >2014-03-11T13:33:56Z DEBUG cn=compat, dc=testrelm,dc=test >2014-03-11T13:33:56Z DEBUG duration: 0 seconds >2014-03-11T13:33:56Z DEBUG [33/34]: tuning directory server >2014-03-11T13:33:56Z DEBUG Starting external process >2014-03-11T13:33:56Z DEBUG args=/usr/sbin/selinuxenabled >2014-03-11T13:33:56Z DEBUG Process finished, return code=0 >2014-03-11T13:33:56Z DEBUG stdout= >2014-03-11T13:33:56Z DEBUG stderr= >2014-03-11T13:33:56Z DEBUG Starting external process >2014-03-11T13:33:56Z DEBUG args=/usr/sbin/restorecon /etc/sysconfig/dirsrv.systemd >2014-03-11T13:33:56Z DEBUG Process finished, return code=0 >2014-03-11T13:33:56Z DEBUG stdout= >2014-03-11T13:33:56Z DEBUG stderr= >2014-03-11T13:33:56Z DEBUG Starting external process >2014-03-11T13:33:56Z DEBUG args=/bin/systemctl --system daemon-reload >2014-03-11T13:33:56Z DEBUG Process finished, return code=0 >2014-03-11T13:33:56Z DEBUG stdout= >2014-03-11T13:33:56Z DEBUG stderr= >2014-03-11T13:33:56Z DEBUG Starting external process >2014-03-11T13:33:56Z DEBUG args=/bin/systemctl --system daemon-reload >2014-03-11T13:33:56Z DEBUG Process finished, return code=0 >2014-03-11T13:33:56Z DEBUG stdout= >2014-03-11T13:33:56Z DEBUG stderr= >2014-03-11T13:33:56Z DEBUG Starting external process >2014-03-11T13:33:56Z DEBUG args=/bin/systemctl restart dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:58Z DEBUG Process finished, return code=0 >2014-03-11T13:33:58Z DEBUG stdout= >2014-03-11T13:33:58Z DEBUG stderr= >2014-03-11T13:33:58Z DEBUG Starting external process >2014-03-11T13:33:58Z DEBUG args=/bin/systemctl is-active dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:58Z DEBUG Process finished, return code=0 >2014-03-11T13:33:58Z DEBUG stdout=active > >2014-03-11T13:33:58Z DEBUG stderr= >2014-03-11T13:33:58Z DEBUG wait_for_open_ports: localhost [389] timeout 300 >2014-03-11T13:33:59Z DEBUG Starting external process >2014-03-11T13:33:59Z DEBUG args=/bin/systemctl is-active dirsrv@TESTRELM-TEST.service >2014-03-11T13:33:59Z DEBUG Process finished, return code=0 >2014-03-11T13:33:59Z DEBUG stdout=active > >2014-03-11T13:33:59Z DEBUG stderr= >2014-03-11T13:33:59Z DEBUG Starting external process >2014-03-11T13:33:59Z DEBUG args=/usr/bin/ldapmodify -v -f /tmp/tmpVwBcy3 -H ldap://rhel70-replica.testrelm.test:389 -x -D cn=Directory Manager -y /tmp/tmpXwt5Wa >2014-03-11T13:33:59Z DEBUG Process finished, return code=0 >2014-03-11T13:33:59Z DEBUG stdout=replace nsslapd-maxdescriptors: > 8192 >replace nsslapd-reservedescriptors: > 64 >modifying entry "cn=config" >modify complete > > >2014-03-11T13:33:59Z DEBUG stderr=ldap_initialize( ldap://rhel70-replica.testrelm.test:389/??base ) > >2014-03-11T13:33:59Z DEBUG duration: 3 seconds >2014-03-11T13:33:59Z DEBUG [34/34]: configuring directory to start on boot >2014-03-11T13:33:59Z DEBUG Starting external process >2014-03-11T13:33:59Z DEBUG args=/bin/systemctl is-enabled dirsrv.target >2014-03-11T13:33:59Z DEBUG Process finished, return code=1 >2014-03-11T13:33:59Z DEBUG stdout=disabled > >2014-03-11T13:33:59Z DEBUG stderr= >2014-03-11T13:33:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:33:59Z DEBUG Starting external process >2014-03-11T13:33:59Z DEBUG args=/bin/systemctl disable dirsrv.target >2014-03-11T13:34:00Z DEBUG Process finished, return code=0 >2014-03-11T13:34:00Z DEBUG stdout= >2014-03-11T13:34:00Z DEBUG stderr= >2014-03-11T13:34:00Z DEBUG duration: 0 seconds >2014-03-11T13:34:00Z DEBUG Done configuring directory server (dirsrv). >2014-03-11T13:34:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:34:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' >2014-03-11T13:34:00Z DEBUG Configuring certificate server (pki-tomcatd): Estimated time 33 minutes 30 seconds >2014-03-11T13:34:00Z DEBUG [1/19]: creating certificate server user >2014-03-11T13:34:00Z DEBUG ca user pkiuser exists >2014-03-11T13:34:00Z DEBUG duration: 0 seconds >2014-03-11T13:34:00Z DEBUG [2/19]: configuring certificate server instance >2014-03-11T13:34:00Z DEBUG Contents of pkispawn configuration file (/tmp/tmp8ZctZ3): >[CA] >pki_security_domain_name = IPA >pki_enable_proxy = True >pki_restart_configured_instance = False >pki_backup_keys = True >pki_backup_password = XXXXXXXX >pki_client_database_dir = /tmp/tmp-FQ5IvJ >pki_client_database_password = XXXXXXXX >pki_client_database_purge = False >pki_client_pkcs12_password = XXXXXXXX >pki_admin_name = admin >pki_admin_uid = admin >pki_admin_email = root@localhost >pki_admin_password = XXXXXXXX >pki_admin_nickname = ipa-ca-agent >pki_admin_subject_dn = cn=ipa-ca-agent,O=TESTRELM.TEST >pki_client_admin_cert_p12 = /root/ca-agent.p12 >pki_ds_ldap_port = 389 >pki_ds_password = XXXXXXXX >pki_ds_base_dn = o=ipaca >pki_ds_database = ipaca >pki_subsystem_subject_dn = cn=CA Subsystem,O=TESTRELM.TEST >pki_ocsp_signing_subject_dn = cn=OCSP Subsystem,O=TESTRELM.TEST >pki_ssl_server_subject_dn = cn=rhel70-replica.testrelm.test,O=TESTRELM.TEST >pki_audit_signing_subject_dn = cn=CA Audit,O=TESTRELM.TEST >pki_ca_signing_subject_dn = cn=Certificate Authority,O=TESTRELM.TEST >pki_subsystem_nickname = subsystemCert cert-pki-ca >pki_ocsp_signing_nickname = ocspSigningCert cert-pki-ca >pki_ssl_server_nickname = Server-Cert cert-pki-ca >pki_audit_signing_nickname = auditSigningCert cert-pki-ca >pki_ca_signing_nickname = caSigningCert cert-pki-ca >pki_security_domain_hostname = hp-dc5800-01.testrelm.test >pki_security_domain_https_port = 443 >pki_security_domain_user = admin >pki_security_domain_password = XXXXXXXX >pki_clone = True >pki_clone_pkcs12_path = /tmp/ca.p12 >pki_clone_pkcs12_password = XXXXXXXX >pki_clone_replication_security = TLS >pki_clone_replication_master_port = 389 > >pki_clone_replication_clone_port = 389 >pki_clone_replicate_schema = False >pki_clone_uri = https://hp-dc5800-01.testrelm.test:443 > > >2014-03-11T13:34:00Z DEBUG Starting external process >2014-03-11T13:34:00Z DEBUG args=/usr/sbin/pkispawn -s CA -f /tmp/tmp8ZctZ3 >2014-03-11T13:34:01Z DEBUG Process finished, return code=1 >2014-03-11T13:34:01Z DEBUG stdout=Loading deployment configuration from /tmp/tmp8ZctZ3. >ERROR: Unable to access security domain: 403 Client Error: Forbidden > >2014-03-11T13:34:01Z DEBUG stderr= >2014-03-11T13:34:01Z CRITICAL failed to configure ca instance Command '/usr/sbin/pkispawn -s CA -f /tmp/tmp8ZctZ3' returned non-zero exit status 1 >2014-03-11T13:34:01Z DEBUG File "/usr/lib/python2.7/site-packages/ipaserver/install/installutils.py", line 622, in run_script > return_value = main_function() > > File "/usr/sbin/ipa-replica-install", line 673, in main > CA = cainstance.install_replica_ca(config, dogtag_master_ds_port) > > File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", line 1680, in install_replica_ca > subject_base=config.subject_base) > > File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", line 478, in configure_instance > self.start_creation(runtime=210) > > File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 364, in start_creation > method() > > File "/usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py", line 604, in __spawn_instance > raise RuntimeError('Configuration of CA failed') > >2014-03-11T13:34:01Z DEBUG The ipa-replica-install command failed, exception: RuntimeError: Configuration of CA failed
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 1075118
: 873161 |
875921