Bug 1748905
| Summary: | [ansible-freeipa] ipa server/replica/client installation failing on client install step | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Varun Mylaraiah <mvarun> | ||||
| Component: | ansible-freeipa | Assignee: | Thomas Woerner <twoerner> | ||||
| Status: | CLOSED ERRATA | QA Contact: | ipa-qe <ipa-qe> | ||||
| Severity: | unspecified | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | 8.1 | CC: | wchadwic | ||||
| Target Milestone: | rc | Keywords: | TestBlocker | ||||
| Target Release: | 8.1 | Flags: | pm-rhel:
mirror+
|
||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | ansible-freeipa-0.1.6-4.el8 | Doc Type: | If docs needed, set a value | ||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2019-11-05 21:09:05 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
Installation failing for Server, Replica, and Client Here is the upstream commit to fix this: https://github.com/freeipa/ansible-freeipa/commit/5bb44245c6c43d752c1e066ebdc6cb3eb0253d98 The upstream commit is simply removing the import of configure_nsswitch_database which is not needed any more in the ipaclient code. Steps to Reproduce:
1) Required 4 RHEL 8.1 Machines (for Controller, Master, Replica and Client)
2) On Controller
a) Add master,replica,client's IP's and hostname's to /etc/hosts
b) Copy ssh key to master, replica and client (like ssh-copy-id -i ~/.ssh/id_rsa.pub root.local)
c) yum install ansible-freeipa
d) yum install python3-pip
e) pip3 install "ansible>=2.8"
f) Copy playbook to the root directory (cp /usr/share/doc/ansible-freeipa/playbooks/install-server.yml . )
3) If DNS issue, copy master IP and hostname to the replica/client machine's /etc/hosts and /etc/resolv.conf
4) On Controller
a) Create inventory like below
# cat inventory/hosts.cluster
[ipaserver]
ipaserver.test.local
[ipaserver:vars]
ipaserver_setup_dns=yes
ipaserver_auto_forwarders=yes
[ipareplicas]
ipareplica1.test.local
[ipareplicas:vars]
ipaclient_force_join=yes
[ipaclients]
ipaclient1.test.local
[ipaclients:vars]
ipaclient_allow_repair=yes
[ipa:children]
ipaserver
ipareplicas
ipaclients
[ipa:vars]
ipaadmin_password=<xxxxxxxxxxxxx>
ipadm_password=<xxxxxxxxxxxxx>
ipaserver_domain=test.local
ipaserver_realm=TEST.LOCAL
b) Run ansible-freeipa playbook (ansible-playbook -vv -i inventory/hosts.cluster install-cluster.yml)
Created attachment 1611504 [details]
logs
Verified
All roles(Server, Replica, and Client) deployed successfully with ansible-freeipa-0.1.6-4.el8.noarch on RHEL 8.1
Console output:
===============
[root@kvm-03-guest03 ~]# ansible-playbook -vv -i hosts.cluster install-cluster.yml
ansible-playbook 2.8.4
config file = None
configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
ansible python module location = /usr/local/lib/python3.6/site-packages/ansible
executable location = /usr/local/bin/ansible-playbook
python version = 3.6.8 (default, Aug 29 2019, 22:00:26) [GCC 8.3.1 20190507 (Red Hat 8.3.1-4)]
No config file found; using defaults
PLAYBOOK: install-cluster.yml ***************************************************************************************
3 plays in install-cluster.yml
PLAY [Install IPA servers] ******************************************************************************************
TASK [Gathering Facts] **********************************************************************************************
task path: /root/install-cluster.yml:2
ok: [ipaserver.test.local]
META: ran handlers
TASK [ipaserver : Import variables specific to distribution] ********************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/main.yml:4
ok: [ipaserver.test.local] => (item=/usr/share/ansible/roles/ipaserver/vars/RedHat-8.yml) => {"ansible_facts": {"ipaserver_packages": ["@idm:DL1/server"], "ipaserver_packages_adtrust": ["@idm:DL1/adtrust"], "ipaserver_packages_dns": ["@idm:DL1/dns"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipaserver/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipaserver/vars/RedHat-8.yml"}
TASK [ipaserver : Install IPA server] *******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/main.yml:12
included: /usr/share/ansible/roles/ipaserver/tasks/install.yml for ipaserver.test.local
TASK [ipaserver : Install - Ensure that IPA server packages are installed] ******************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:5
changed: [ipaserver.test.local] => {"changed": true, "msg": "", "rc": 0, "results": ["Module idm:DL1/server installed.", "Installed: sssd-tools-2.2.0-18.el8.x86_64", "Installed:
*
*
*
*
TASK [ipaserver : Install - Ensure that IPA server packages for dns are installed] **********************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:10
changed: [ipaserver.test.local] => {"changed": true, "msg": "", "rc": 0, "results": ["Installed: libitm-8.3.1-4.5.el8.x86_64", "Installed: opencryptoki-3.11.1-2.el8.x86_64", "Installed: opendnssec-1.4.14-1.module+el8.1.0+4098+f286395e.x86_64", "Installed: sqlite-3.26.0-3.el8.x86_64", "Installed: bind-32:9.11.4-26.P2.el8.x86_64", "Installed: bind-dyndb-ldap-11.1-14.module+el8.1.0+4098+f286395e.x86_64", "Installed: ldns-1.7.0-21.el8.x86_64", "Installed: bind-pkcs11-32:9.11.4-26.P2.el8.x86_64", "Installed: bind-pkcs11-libs-32:9.11.4-26.P2.el8.x86_64", "Installed: bind-pkcs11-utils-32:9.11.4-26.P2.el8.x86_64", "Installed: opencryptoki-icsftok-3.11.1-2.el8.x86_64", "Installed: ipa-server-dns-4.8.0-10.module+el8.1.0+4098+f286395e.noarch", "Installed: opencryptoki-libs-3.11.1-2.el8.x86_64"]}
TASK [ipaserver : Install - Ensure that IPA server packages for adtrust are installed] ******************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:16
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaserver : include_tasks] ************************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:27
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaserver : Install - Server installation test] ***************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:33
ok: [ipaserver.test.local] => {"_dirsrv_ca_cert": null, "_dirsrv_pkcs12_file": null, "_dirsrv_pkcs12_info": null, "_hostname_overridden": true, "_http_ca_cert": null, "_http_pkcs12_file": null, "_http_pkcs12_info": null, "_installation_cleanup": true, "_pkinit_ca_cert": null, "_pkinit_pkcs12_file": null, "_pkinit_pkcs12_info": null, "changed": false, "domain": "test.local", "domainlevel": 1, "external_ca": false, "external_ca_profile": null, "external_ca_type": null, "hostname": "ipaserver.test.local", "idmax": 247999999, "idstart": 247800000, "ipa_python_version": 40800, "no_host_dns": true, "no_pkinit": false, "ntp_pool": null, "ntp_servers": null, "realm": "TEST.LOCAL", "rid_base": 1000, "secondary_rid_base": 100000000, "setup_adtrust": false, "setup_ca": true, "setup_kra": false}
TASK [ipaserver : Install - Master password creation] ***************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:110
changed: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": true}
TASK [ipaserver : Install - Use new master password] ****************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:117
ok: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaserver : Install - Server preparation] *********************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:125
changed: [ipaserver.test.local] => {"_ca_subject": "CN=Certificate Authority,O=TEST.LOCAL", "_subject_base": "O=TEST.LOCAL", "adtrust_netbios_name": null, "adtrust_reset_netbios_name": false, "ca_subject": "CN=Certificate Authority,O=TEST.LOCAL", "changed": true, "dns_ip_addresses": ["2620:52:0:1038:5054:ff:fedf:5fc0", "fec0::f101:5054:ff:fedf:5fc0", "10.16.56.125"], "dns_reverse_zones": [], "forward_policy": "only", "forwarders": ["10.19.42.41", "10.11.5.19", "10.5.30.160"], "ip_addresses": ["2620:52:0:1038:5054:ff:fedf:5fc0", "fec0::f101:5054:ff:fedf:5fc0", "10.16.56.125"], "no_dnssec_validation": false, "reverse_zones": [], "subject_base": "O=TEST.LOCAL"}
TASK [ipaserver : Install - Setup NTP] ******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:169
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaserver : Install - Setup DS] *******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:176
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaserver : Install - Setup KRB] ******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:205
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaserver : Install - Setup custodia] *************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:232
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaserver : Install - Setup CA] *******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:238
changed: [ipaserver.test.local] => {"changed": true, "csr_generated": false}
TASK [ipaserver : Copy /root/ipa.csr to "ipaserver.test.local-ipa.csr"] *********************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:278
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaserver : Install - Setup otpd] *****************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:287
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaserver : Install - Setup HTTP] *****************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:293
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaserver : Install - Setup KRA] ******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:325
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaserver : Install - Setup DNS] ******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:336
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaserver : Install - Setup ADTRUST] **************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:353
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaserver : Install - Set DS password] ************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:368
changed: [ipaserver.test.local] => {"changed": true}
TASK [Install - Setup client] ***************************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:385
TASK [ipaclient : Import variables specific to distribution] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:4
ok: [ipaserver.test.local] => (item=/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml) => {"ansible_facts": {"ipaclient_packages": ["@idm:DL1/client"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"}
TASK [ipaclient : Install IPA client] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:12
included: /usr/share/ansible/roles/ipaclient/tasks/install.yml for ipaserver.test.local
TASK [ipaclient : Install - Ensure that IPA client packages are installed] ******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:4
ok: [ipaserver.test.local] => {"changed": false, "msg": "Nothing to do", "rc": 0, "results": []}
TASK [ipaclient : Install - Set ipaclient_servers] ******************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:13
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Set ipaclient_servers from cluster inventory] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:18
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Check that either principal or keytab is set] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:24
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Set default principal if no keytab is given] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:28
ok: [ipaserver.test.local] => {"ansible_facts": {"ipaadmin_principal": "admin"}, "changed": false}
TASK [ipaclient : Install - IPA client test] ************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:33
ok: [ipaserver.test.local] => {"basedn": "dc=test,dc=local", "changed": false, "client_already_configured": false, "client_domain": "test.local", "dnsok": false, "domain": "test.local", "hostname": "ipaserver.test.local", "ipa_python_version": 40800, "kdc": "ipaserver.test.local", "ntp_pool": null, "ntp_servers": null, "realm": "TEST.LOCAL", "servers": ["ipaserver.test.local"], "sssd": true}
TASK [ipaclient : Install - Cleanup leftover ccache] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:58
ok: [ipaserver.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}
TASK [ipaclient : Install - Configure NTP] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:63
ok: [ipaserver.test.local] => {"changed": false}
TASK [ipaclient : Install - Disable One-Time Password for on_master] ************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:75
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Test if IPA client has working krb5.keytab] *********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:80
ok: [ipaserver.test.local] => {"ca_crt_exists": true, "changed": false, "krb5_conf_ok": true, "krb5_keytab_ok": true, "ping_test_ok": false}
TASK [ipaclient : Install - Disable One-Time Password for client with working krb5.keytab] **************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:90
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Keytab or password is required for otp] *************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:105
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Get One-Time Password for client enrollment] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:113
skipping: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaclient : Install - Report error for OTP generation] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:133
skipping: [ipaserver.test.local] => {}
TASK [ipaclient : Install - Store the previously obtained OTP] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:139
skipping: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaclient : Install - Check if principal and keytab are set] **************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:157
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Check if one of password or keytabs are set] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:161
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Purge TEST.LOCAL from host keytab] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:169
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Backup and set hostname] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:182
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Join IPA] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:187
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:209
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:214
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:217
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Configure IPA default.conf] *************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:229
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Configure SSSD] *************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:238
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure krb5 for IPA realm] ***********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:255
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - IPA API calls for remaining enrollment parts] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:269
changed: [ipaserver.test.local] => {"ca_enabled": true, "changed": true, "subject_base": "O=TEST.LOCAL"}
TASK [ipaclient : Install - Fix IPA ca] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:277
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Create IPA NSS database] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:287
changed: [ipaserver.test.local] => {"ca_enabled_ra": true, "changed": true}
TASK [ipaclient : Install - Configure SSH and SSHD] *****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:313
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure automount] ********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:321
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure firefox] **********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:327
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Configure NIS] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:332
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaclient : Install - Restore original admin password if overwritten by OTP] **********************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:350
skipping: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaclient : Cleanup leftover ccache] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:356
ok: [ipaserver.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}
TASK [ipaclient : Uninstall IPA client] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:16
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaserver : Install - Enable IPA] *****************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:400
changed: [ipaserver.test.local] => {"changed": true}
TASK [ipaserver : Install - Cleanup root IPA cache] *****************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:407
ok: [ipaserver.test.local] => {"changed": false, "path": "/root/.ipa_cache", "state": "absent"}
TASK [ipaserver : Install - Configure firewalld] ********************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:413
changed: [ipaserver.test.local] => {"changed": true, "cmd": ["firewall-cmd", "--permanent", "--add-service=freeipa-ldap", "--add-service=freeipa-ldaps", "--add-service=dns", "--add-service=ntp"], "delta": "0:00:00.375260", "end": "2019-09-06 12:07:02.865031", "rc": 0, "start": "2019-09-06 12:07:02.489771", "stderr": "", "stderr_lines": [], "stdout": "success", "stdout_lines": ["success"]}
TASK [ipaserver : Install - Configure firewalld runtime] ************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:425
changed: [ipaserver.test.local] => {"changed": true, "cmd": ["firewall-cmd", "--add-service=freeipa-ldap", "--add-service=freeipa-ldaps", "--add-service=dns", "--add-service=ntp"], "delta": "0:00:00.464001", "end": "2019-09-06 12:07:03.773223", "rc": 0, "start": "2019-09-06 12:07:03.309222", "stderr": "", "stderr_lines": [], "stdout": "success", "stdout_lines": ["success"]}
TASK [ipaserver : Uninstall IPA server] *****************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/main.yml:16
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
META: ran handlers
META: ran handlers
PLAY [Install IPA replicas] *****************************************************************************************
TASK [Gathering Facts] **********************************************************************************************
task path: /root/install-cluster.yml:10
ok: [ipareplica1.test.local]
META: ran handlers
TASK [ipareplica : Import variables specific to distribution] *******************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/main.yml:4
ok: [ipareplica1.test.local] => (item=/usr/share/ansible/roles/ipareplica/vars/RedHat-8.yml) => {"ansible_facts": {"ipareplica_packages": ["@idm:DL1/server"], "ipareplica_packages_adtrust": ["@idm:DL1/adtrust"], "ipareplica_packages_dns": ["@idm:DL1/dns"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipareplica/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipareplica/vars/RedHat-8.yml"}
TASK [ipareplica : Install IPA replica] *****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/main.yml:12
included: /usr/share/ansible/roles/ipareplica/tasks/install.yml for ipareplica1.test.local
TASK [ipareplica : Install - Ensure IPA replica packages are installed] *********************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:6
changed: [ipareplica1.test.local] => {"changed": true, "msg": "", "rc": 0, "results": ["Module idm:DL1/server installed.", "Installed: sssd-tools-2.2.0-18.el8.x86_64", "Installed:
*
*
*
TASK [ipareplica : Install - Ensure IPA replica packages for dns are installed] *************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:11
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipareplica : Install - Ensure IPA replica packages for adtrust are installed] *********************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:17
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipareplica : Install - Set ipareplica_servers] ****************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:28
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipareplica : Install - Set default principal if no keytab is given] *******************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:33
ok: [ipareplica1.test.local] => {"ansible_facts": {"ipaadmin_principal": "admin"}, "changed": false}
TASK [ipareplica : Install - Replica installation test] *************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:38
ok: [ipareplica1.test.local] => {"change_master_for_certmonger": true, "changed": false, "client_enrolled": false, "domain": "test.local", "hostname": "ipareplica1.test.local", "ipa_python_version": 40800, "realm": "TEST.LOCAL", "server": null, "setup_adtrust": false, "setup_kra": false}
TASK [Install - Setup client] ***************************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:81
TASK [ipaclient : Import variables specific to distribution] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:4
ok: [ipareplica1.test.local] => (item=/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml) => {"ansible_facts": {"ipaclient_packages": ["@idm:DL1/client"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"}
TASK [ipaclient : Install IPA client] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:12
included: /usr/share/ansible/roles/ipaclient/tasks/install.yml for ipareplica1.test.local
TASK [ipaclient : Install - Ensure that IPA client packages are installed] ******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:4
ok: [ipareplica1.test.local] => {"changed": false, "msg": "Nothing to do", "rc": 0, "results": []}
TASK [ipaclient : Install - Set ipaclient_servers] ******************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:13
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Set ipaclient_servers from cluster inventory] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:18
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Check that either principal or keytab is set] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:24
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Set default principal if no keytab is given] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:28
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - IPA client test] ************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:33
ok: [ipareplica1.test.local] => {"basedn": "dc=test,dc=local", "changed": false, "client_already_configured": false, "client_domain": "test.local", "dnsok": true, "domain": "test.local", "hostname": "ipareplica1.test.local", "ipa_python_version": 40800, "kdc": "ipaserver.test.local", "ntp_pool": null, "ntp_servers": null, "realm": "TEST.LOCAL", "servers": ["ipaserver.test.local"], "sssd": true}
TASK [ipaclient : Install - Cleanup leftover ccache] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:58
ok: [ipareplica1.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}
TASK [ipaclient : Install - Configure NTP] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:63
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipaclient : Install - Disable One-Time Password for on_master] ************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:75
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Test if IPA client has working krb5.keytab] *********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:80
ok: [ipareplica1.test.local] => {"ca_crt_exists": false, "changed": false, "krb5_conf_ok": false, "krb5_keytab_ok": false, "ping_test_ok": false}
TASK [ipaclient : Install - Disable One-Time Password for client with working krb5.keytab] **************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:90
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Keytab or password is required for otp] *************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:105
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Get One-Time Password for client enrollment] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:113
skipping: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaclient : Install - Report error for OTP generation] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:133
skipping: [ipareplica1.test.local] => {}
TASK [ipaclient : Install - Store the previously obtained OTP] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:139
skipping: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaclient : Install - Check if principal and keytab are set] **************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:157
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Check if one of password or keytabs are set] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:161
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Purge TEST.LOCAL from host keytab] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:169
changed: [ipareplica1.test.local] => {"changed": true, "cmd": ["/usr/sbin/ipa-rmkeytab", "-k", "/etc/krb5.keytab", "-r", "TEST.LOCAL"], "delta": "0:00:00.004798", "end": "2019-09-06 12:08:12.561831", "failed_when_result": false, "msg": "non-zero return code", "rc": 3, "start": "2019-09-06 12:08:12.557033", "stderr": "Failed to open keytab '/etc/krb5.keytab': No such file or directory", "stderr_lines": ["Failed to open keytab '/etc/krb5.keytab': No such file or directory"], "stdout": "", "stdout_lines": []}
TASK [ipaclient : Install - Backup and set hostname] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:182
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipaclient : Install - Join IPA] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:187
changed: [ipareplica1.test.local] => {"already_joined": false, "changed": true}
TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:209
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:214
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:217
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Configure IPA default.conf] *************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:229
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure SSSD] *************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:238
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure krb5 for IPA realm] ***********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:255
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipaclient : Install - IPA API calls for remaining enrollment parts] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:269
changed: [ipareplica1.test.local] => {"ca_enabled": true, "changed": true, "subject_base": "O=TEST.LOCAL"}
TASK [ipaclient : Install - Fix IPA ca] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:277
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Create IPA NSS database] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:287
changed: [ipareplica1.test.local] => {"ca_enabled_ra": true, "changed": true}
TASK [ipaclient : Install - Configure SSH and SSHD] *****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:313
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure automount] ********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:321
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure firefox] **********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:327
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Configure NIS] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:332
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipaclient : Install - Restore original admin password if overwritten by OTP] **********************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:350
skipping: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaclient : Cleanup leftover ccache] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:356
ok: [ipareplica1.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}
TASK [ipaclient : Uninstall IPA client] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:16
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipareplica : Install - Configure firewalld] *******************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:95
changed: [ipareplica1.test.local] => {"changed": true, "cmd": ["firewall-cmd", "--permanent", "--add-service=freeipa-ldap", "--add-service=freeipa-ldaps", "--add-service=ntp"], "delta": "0:00:00.377143", "end": "2019-09-06 12:08:34.508746", "rc": 0, "start": "2019-09-06 12:08:34.131603", "stderr": "", "stderr_lines": [], "stdout": "success", "stdout_lines": ["success"]}
TASK [ipareplica : Install - Configure firewalld runtime] ***********************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:107
changed: [ipareplica1.test.local] => {"changed": true, "cmd": ["firewall-cmd", "--add-service=freeipa-ldap", "--add-service=freeipa-ldaps", "--add-service=ntp"], "delta": "0:00:00.415088", "end": "2019-09-06 12:08:35.440946", "rc": 0, "start": "2019-09-06 12:08:35.025858", "stderr": "", "stderr_lines": [], "stdout": "success", "stdout_lines": ["success"]}
TASK [ipareplica : Install - Replica preparation] *******************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:118
changed: [ipareplica1.test.local] => {"_add_to_ipaservers": true, "_ca_enabled": true, "_ca_file": "/etc/ipa/ca.crt", "_ca_subject": "CN=Certificate Authority,O=TEST.LOCAL", "_dirsrv_ca_cert": null, "_dirsrv_pkcs12_file": null, "_dirsrv_pkcs12_info": null, "_http_ca_cert": null, "_http_pkcs12_file": null, "_http_pkcs12_info": null, "_kra_enabled": false, "_pkinit_ca_cert": null, "_pkinit_pkcs12_file": null, "_pkinit_pkcs12_info": null, "_subject_base": "O=TEST.LOCAL", "_top_dir": "/tmp/tmpqxh5lpceipa", "adtrust_netbios_name": null, "adtrust_reset_netbios_name": false, "ccache": "/tmp/krbccb5itlmmn/ccache", "changed": true, "config_ca_host_name": "ipaserver.test.local", "config_ips": ["10.16.56.179"], "config_kra_host_name": "ipaserver.test.local", "config_master_host_name": "ipaserver.test.local", "config_setup_ca": false, "dns_ip_addresses": [], "dns_reverse_zones": [], "forward_policy": null, "installer_ccache": "/tmp/tmpajr0ol72", "no_dnssec_validation": null, "rid_base": 1000, "secondary_rid_base": 100000000, "subject_base": "O=TEST.LOCAL"}
TASK [ipareplica : Install - Add to ipaservers] *********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:173
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Create dirman password] ****************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:185
changed: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": true}
TASK [ipareplica : Install - Set dirman password] *******************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:191
ok: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipareplica : Install - Setup certmonger] **********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:197
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Install CA certs] **********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:201
changed: [ipareplica1.test.local] => {"changed": true, "config_ca_host_name": "ipaserver.test.local", "config_master_host_name": "ipaserver.test.local"}
TASK [ipareplica : Install - Setup DS] ******************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:241
changed: [ipareplica1.test.local] => {"changed": true, "ds_ca_subject": "CN=Certificate Authority,O=TEST.LOCAL", "ds_suffix": "dc=test,dc=local"}
TASK [ipareplica : Install - Create IPA conf] ***********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:285
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Setup KRB] *****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:323
changed: [ipareplica1.test.local] => {"changed": true, "config_master_host_name": "ipaserver.test.local"}
TASK [ipareplica : Install - Create override IPA conf] **************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:341
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - DS enable SSL] *************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:382
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Setup http] ****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:402
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Create original IPA conf again] ********************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:423
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Setup otpd] ****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:462
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Setup custodia] ************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:479
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Setup CA] ******************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:500
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - KRB enable SSL] ************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:529
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - DS apply updates] **********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:547
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Setup kra] *****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:568
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipareplica : Install - Restart KDC] ***************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:607
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Custodia import dm password] ***********************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:624
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Promote SSSD] **************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:646
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Promote openldap.conf] *****************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:659
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Setup DNS] *****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:672
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Setup adtrust] *************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:696
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipareplica : Install - Enable IPA] ****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:718
changed: [ipareplica1.test.local] => {"changed": true}
TASK [ipareplica : Install - Cleanup root IPA cache] ****************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:735
ok: [ipareplica1.test.local] => {"changed": false, "path": "/root/.ipa_cache", "state": "absent"}
TASK [ipareplica : Uninstall IPA replica] ***************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/main.yml:16
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
META: ran handlers
META: ran handlers
PLAY [Install IPA clients] ******************************************************************************************
TASK [Gathering Facts] **********************************************************************************************
task path: /root/install-cluster.yml:18
ok: [ipaclient1.test.local]
META: ran handlers
TASK [ipaclient : Import variables specific to distribution] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:4
ok: [ipaclient1.test.local] => (item=/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml) => {"ansible_facts": {"ipaclient_packages": ["@idm:DL1/client"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"}
TASK [ipaclient : Install IPA client] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:12
included: /usr/share/ansible/roles/ipaclient/tasks/install.yml for ipaclient1.test.local
TASK [ipaclient : Install - Ensure that IPA client packages are installed] ******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:4
changed: [ipaclient1.test.local] => {"changed": true, "msg": "", "rc": 0, "results": ["Module idm:DL1/client installed.", "Installed: ipa-client-4.8.0-10.module+el8.1.0+4098+f286395e.x86_64", "Installed: python3-qrcode-core-5.1-12.module+el8.1.0+4098+f286395e.noarch", "Installed: ipa-client-common-4.8.0-10.module+el8.1.0+4098+f286395e.noarch", "Installed:
*
*
*
*
TASK [ipaclient : Install - Set ipaclient_servers] ******************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:13
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Set ipaclient_servers from cluster inventory] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:18
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Check that either principal or keytab is set] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:24
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Set default principal if no keytab is given] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:28
ok: [ipaclient1.test.local] => {"ansible_facts": {"ipaadmin_principal": "admin"}, "changed": false}
TASK [ipaclient : Install - IPA client test] ************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:33
ok: [ipaclient1.test.local] => {"basedn": "dc=test,dc=local", "changed": false, "client_already_configured": false, "client_domain": "test.local", "dnsok": true, "domain": "test.local", "hostname": "ipaclient1.test.local", "ipa_python_version": 40800, "kdc": "ipareplica1.test.local,ipaserver.test.local", "ntp_pool": null, "ntp_servers": null, "realm": "TEST.LOCAL", "servers": ["ipareplica1.test.local"], "sssd": true}
TASK [ipaclient : Install - Cleanup leftover ccache] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:58
ok: [ipaclient1.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}
TASK [ipaclient : Install - Configure NTP] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:63
changed: [ipaclient1.test.local] => {"changed": true}
TASK [ipaclient : Install - Disable One-Time Password for on_master] ************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:75
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Test if IPA client has working krb5.keytab] *********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:80
ok: [ipaclient1.test.local] => {"ca_crt_exists": false, "changed": false, "krb5_conf_ok": false, "krb5_keytab_ok": false, "ping_test_ok": false}
TASK [ipaclient : Install - Disable One-Time Password for client with working krb5.keytab] **************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:90
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Keytab or password is required for otp] *************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:105
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Get One-Time Password for client enrollment] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:113
skipping: [ipaclient1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaclient : Install - Report error for OTP generation] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:133
skipping: [ipaclient1.test.local] => {}
TASK [ipaclient : Install - Store the previously obtained OTP] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:139
skipping: [ipaclient1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaclient : Install - Check if principal and keytab are set] **************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:157
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Check if one of password or keytabs are set] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:161
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Purge TEST.LOCAL from host keytab] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:169
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Backup and set hostname] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:182
changed: [ipaclient1.test.local] => {"changed": true}
TASK [ipaclient : Install - Join IPA] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:187
changed: [ipaclient1.test.local] => {"already_joined": false, "changed": true}
TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:209
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:214
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:217
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Configure IPA default.conf] *************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:229
changed: [ipaclient1.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure SSSD] *************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:238
changed: [ipaclient1.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure krb5 for IPA realm] ***********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:255
changed: [ipaclient1.test.local] => {"changed": true}
TASK [ipaclient : Install - IPA API calls for remaining enrollment parts] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:269
changed: [ipaclient1.test.local] => {"ca_enabled": true, "changed": true, "subject_base": "O=TEST.LOCAL"}
TASK [ipaclient : Install - Fix IPA ca] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:277
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Create IPA NSS database] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:287
changed: [ipaclient1.test.local] => {"ca_enabled_ra": true, "changed": true}
TASK [ipaclient : Install - Configure SSH and SSHD] *****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:313
changed: [ipaclient1.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure automount] ********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:321
changed: [ipaclient1.test.local] => {"changed": true}
TASK [ipaclient : Install - Configure firefox] **********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:327
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
TASK [ipaclient : Install - Configure NIS] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:332
changed: [ipaclient1.test.local] => {"changed": true}
TASK [ipaclient : Install - Restore original admin password if overwritten by OTP] **********************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:350
skipping: [ipaclient1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}
TASK [ipaclient : Cleanup leftover ccache] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:356
ok: [ipaclient1.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}
TASK [ipaclient : Uninstall IPA client] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:16
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
META: ran handlers
META: ran handlers
PLAY RECAP **********************************************************************************************************
ipaclient1.test.local : ok=20 changed=12 unreachable=0 failed=0 skipped=19 rescued=0 ignored=0
ipareplica1.test.local : ok=52 changed=38 unreachable=0 failed=0 skipped=25 rescued=0 ignored=0
ipaserver.test.local : ok=37 changed=22 unreachable=0 failed=0 skipped=29 rescued=0 ignored=0
Based on the above observation, marking the bug VERIFIED
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2019:3418 |
Description of problem: Ansible-freeipa server installation is failing on client install step with ipa-server-4.8.0-10.module+el8.1.0+4098+f286395e.x86_64 in RHEL-8.1 Version-Release number of selected component (if applicable): ansible-freeipa-0.1.6-3.el8.noarch How reproducible: 100% Error ======= fatal: [ipaserver.test.local]: FAILED! => {"changed": false, "module_stderr": "Shared connection to ipaserver.test.local closed.\r\n", "module_stdout": "This program will set up IPA client.\r\nVersion 4.8.0\r\n\r\nIPA client is already configured on this system.\r\nIf you want to reinstall the IPA client, uninstall it first using 'ipa-client-install --uninstall'.\r\nThe ipa-client-install command failed. See /var/log/ipaclient-install.log for more information\r\n", "msg": "MODULE FAILURE\nSee stdout/stderr for the exact error", "rc": 3} Additional info: