Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1748905

Summary: [ansible-freeipa] ipa server/replica/client installation failing on client install step
Product: Red Hat Enterprise Linux 8 Reporter: Varun Mylaraiah <mvarun>
Component: ansible-freeipaAssignee: Thomas Woerner <twoerner>
Status: CLOSED ERRATA QA Contact: ipa-qe <ipa-qe>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8.1CC: wchadwic
Target Milestone: rcKeywords: TestBlocker
Target Release: 8.1Flags: pm-rhel: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ansible-freeipa-0.1.6-4.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-11-05 21:09:05 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
logs none

Description Varun Mylaraiah 2019-09-04 12:18:33 UTC
Description of problem:
Ansible-freeipa server installation is failing on client install step with ipa-server-4.8.0-10.module+el8.1.0+4098+f286395e.x86_64 in RHEL-8.1


Version-Release number of selected component (if applicable):
ansible-freeipa-0.1.6-3.el8.noarch

How reproducible:
100%


Error
=======
fatal: [ipaserver.test.local]: FAILED! => {"changed": false, "module_stderr": "Shared connection to ipaserver.test.local closed.\r\n", "module_stdout": "This program will set up IPA client.\r\nVersion 4.8.0\r\n\r\nIPA client is already configured on this system.\r\nIf you want to reinstall the IPA client, uninstall it first using 'ipa-client-install --uninstall'.\r\nThe ipa-client-install command failed. See /var/log/ipaclient-install.log for more information\r\n", "msg": "MODULE FAILURE\nSee stdout/stderr for the exact error", "rc": 3}


Additional info:

Comment 2 Varun Mylaraiah 2019-09-04 12:39:52 UTC
Installation failing for Server, Replica, and Client

Comment 3 Thomas Woerner 2019-09-04 12:52:16 UTC
Here is the upstream commit to fix this: https://github.com/freeipa/ansible-freeipa/commit/5bb44245c6c43d752c1e066ebdc6cb3eb0253d98

Comment 4 Thomas Woerner 2019-09-04 12:53:37 UTC
The upstream commit is simply removing the import of configure_nsswitch_database which is not needed any more in the ipaclient code.

Comment 5 Varun Mylaraiah 2019-09-04 13:11:01 UTC
Steps to Reproduce:
1) Required 4 RHEL 8.1 Machines (for Controller, Master, Replica and Client)
2) On Controller
	a) Add master,replica,client's IP's and hostname's to /etc/hosts
	b) Copy ssh key to master, replica and client (like ssh-copy-id -i ~/.ssh/id_rsa.pub root.local)
	c) yum install ansible-freeipa
	d) yum install python3-pip
	e) pip3 install "ansible>=2.8"
	f) Copy playbook to the root directory (cp /usr/share/doc/ansible-freeipa/playbooks/install-server.yml . )
3) If DNS issue, copy master IP and hostname to the replica/client machine's /etc/hosts and /etc/resolv.conf
4) On Controller
	a) Create inventory like below
	
		# cat inventory/hosts.cluster 
		[ipaserver]
		ipaserver.test.local
		
		[ipaserver:vars]
		ipaserver_setup_dns=yes
		ipaserver_auto_forwarders=yes
 
		[ipareplicas]
		ipareplica1.test.local
 
		[ipareplicas:vars]
		ipaclient_force_join=yes
 
		[ipaclients]
		ipaclient1.test.local
 
		[ipaclients:vars]
		ipaclient_allow_repair=yes
 
		[ipa:children]
		ipaserver
		ipareplicas
		ipaclients
 
		[ipa:vars]
		ipaadmin_password=<xxxxxxxxxxxxx>
		ipadm_password=<xxxxxxxxxxxxx>
		ipaserver_domain=test.local
		ipaserver_realm=TEST.LOCAL

        b) Run ansible-freeipa playbook	(ansible-playbook -vv -i inventory/hosts.cluster install-cluster.yml)

Comment 6 Varun Mylaraiah 2019-09-04 13:13:24 UTC
Created attachment 1611504 [details]
logs

Comment 10 Varun Mylaraiah 2019-09-06 16:28:14 UTC
Verified

All roles(Server, Replica, and Client) deployed successfully with ansible-freeipa-0.1.6-4.el8.noarch on RHEL 8.1


Console output:
===============
[root@kvm-03-guest03 ~]# ansible-playbook -vv -i hosts.cluster install-cluster.yml 
ansible-playbook 2.8.4
  config file = None
  configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
  ansible python module location = /usr/local/lib/python3.6/site-packages/ansible
  executable location = /usr/local/bin/ansible-playbook
  python version = 3.6.8 (default, Aug 29 2019, 22:00:26) [GCC 8.3.1 20190507 (Red Hat 8.3.1-4)]
No config file found; using defaults

PLAYBOOK: install-cluster.yml ***************************************************************************************
3 plays in install-cluster.yml

PLAY [Install IPA servers] ******************************************************************************************

TASK [Gathering Facts] **********************************************************************************************
task path: /root/install-cluster.yml:2
ok: [ipaserver.test.local]
META: ran handlers

TASK [ipaserver : Import variables specific to distribution] ********************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/main.yml:4
ok: [ipaserver.test.local] => (item=/usr/share/ansible/roles/ipaserver/vars/RedHat-8.yml) => {"ansible_facts": {"ipaserver_packages": ["@idm:DL1/server"], "ipaserver_packages_adtrust": ["@idm:DL1/adtrust"], "ipaserver_packages_dns": ["@idm:DL1/dns"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipaserver/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipaserver/vars/RedHat-8.yml"}

TASK [ipaserver : Install IPA server] *******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/main.yml:12
included: /usr/share/ansible/roles/ipaserver/tasks/install.yml for ipaserver.test.local

TASK [ipaserver : Install - Ensure that IPA server packages are installed] ******************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:5
changed: [ipaserver.test.local] => {"changed": true, "msg": "", "rc": 0, "results": ["Module idm:DL1/server installed.", "Installed: sssd-tools-2.2.0-18.el8.x86_64", "Installed:
	*
	*
	*
	*
TASK [ipaserver : Install - Ensure that IPA server packages for dns are installed] **********************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:10
changed: [ipaserver.test.local] => {"changed": true, "msg": "", "rc": 0, "results": ["Installed: libitm-8.3.1-4.5.el8.x86_64", "Installed: opencryptoki-3.11.1-2.el8.x86_64", "Installed: opendnssec-1.4.14-1.module+el8.1.0+4098+f286395e.x86_64", "Installed: sqlite-3.26.0-3.el8.x86_64", "Installed: bind-32:9.11.4-26.P2.el8.x86_64", "Installed: bind-dyndb-ldap-11.1-14.module+el8.1.0+4098+f286395e.x86_64", "Installed: ldns-1.7.0-21.el8.x86_64", "Installed: bind-pkcs11-32:9.11.4-26.P2.el8.x86_64", "Installed: bind-pkcs11-libs-32:9.11.4-26.P2.el8.x86_64", "Installed: bind-pkcs11-utils-32:9.11.4-26.P2.el8.x86_64", "Installed: opencryptoki-icsftok-3.11.1-2.el8.x86_64", "Installed: ipa-server-dns-4.8.0-10.module+el8.1.0+4098+f286395e.noarch", "Installed: opencryptoki-libs-3.11.1-2.el8.x86_64"]}

TASK [ipaserver : Install - Ensure that IPA server packages for adtrust are installed] ******************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:16
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaserver : include_tasks] ************************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:27
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaserver : Install - Server installation test] ***************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:33
ok: [ipaserver.test.local] => {"_dirsrv_ca_cert": null, "_dirsrv_pkcs12_file": null, "_dirsrv_pkcs12_info": null, "_hostname_overridden": true, "_http_ca_cert": null, "_http_pkcs12_file": null, "_http_pkcs12_info": null, "_installation_cleanup": true, "_pkinit_ca_cert": null, "_pkinit_pkcs12_file": null, "_pkinit_pkcs12_info": null, "changed": false, "domain": "test.local", "domainlevel": 1, "external_ca": false, "external_ca_profile": null, "external_ca_type": null, "hostname": "ipaserver.test.local", "idmax": 247999999, "idstart": 247800000, "ipa_python_version": 40800, "no_host_dns": true, "no_pkinit": false, "ntp_pool": null, "ntp_servers": null, "realm": "TEST.LOCAL", "rid_base": 1000, "secondary_rid_base": 100000000, "setup_adtrust": false, "setup_ca": true, "setup_kra": false}

TASK [ipaserver : Install - Master password creation] ***************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:110
changed: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": true}

TASK [ipaserver : Install - Use new master password] ****************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:117
ok: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaserver : Install - Server preparation] *********************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:125
changed: [ipaserver.test.local] => {"_ca_subject": "CN=Certificate Authority,O=TEST.LOCAL", "_subject_base": "O=TEST.LOCAL", "adtrust_netbios_name": null, "adtrust_reset_netbios_name": false, "ca_subject": "CN=Certificate Authority,O=TEST.LOCAL", "changed": true, "dns_ip_addresses": ["2620:52:0:1038:5054:ff:fedf:5fc0", "fec0::f101:5054:ff:fedf:5fc0", "10.16.56.125"], "dns_reverse_zones": [], "forward_policy": "only", "forwarders": ["10.19.42.41", "10.11.5.19", "10.5.30.160"], "ip_addresses": ["2620:52:0:1038:5054:ff:fedf:5fc0", "fec0::f101:5054:ff:fedf:5fc0", "10.16.56.125"], "no_dnssec_validation": false, "reverse_zones": [], "subject_base": "O=TEST.LOCAL"}

TASK [ipaserver : Install - Setup NTP] ******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:169
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaserver : Install - Setup DS] *******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:176
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaserver : Install - Setup KRB] ******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:205
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaserver : Install - Setup custodia] *************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:232
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaserver : Install - Setup CA] *******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:238
changed: [ipaserver.test.local] => {"changed": true, "csr_generated": false}

TASK [ipaserver : Copy /root/ipa.csr to "ipaserver.test.local-ipa.csr"] *********************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:278
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaserver : Install - Setup otpd] *****************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:287
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaserver : Install - Setup HTTP] *****************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:293
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaserver : Install - Setup KRA] ******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:325
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaserver : Install - Setup DNS] ******************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:336
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaserver : Install - Setup ADTRUST] **************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:353
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaserver : Install - Set DS password] ************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:368
changed: [ipaserver.test.local] => {"changed": true}

TASK [Install - Setup client] ***************************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:385

TASK [ipaclient : Import variables specific to distribution] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:4
ok: [ipaserver.test.local] => (item=/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml) => {"ansible_facts": {"ipaclient_packages": ["@idm:DL1/client"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"}

TASK [ipaclient : Install IPA client] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:12
included: /usr/share/ansible/roles/ipaclient/tasks/install.yml for ipaserver.test.local

TASK [ipaclient : Install - Ensure that IPA client packages are installed] ******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:4
ok: [ipaserver.test.local] => {"changed": false, "msg": "Nothing to do", "rc": 0, "results": []}

TASK [ipaclient : Install - Set ipaclient_servers] ******************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:13
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Set ipaclient_servers from cluster inventory] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:18
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Check that either principal or keytab is set] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:24
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Set default principal if no keytab is given] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:28
ok: [ipaserver.test.local] => {"ansible_facts": {"ipaadmin_principal": "admin"}, "changed": false}

TASK [ipaclient : Install - IPA client test] ************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:33
ok: [ipaserver.test.local] => {"basedn": "dc=test,dc=local", "changed": false, "client_already_configured": false, "client_domain": "test.local", "dnsok": false, "domain": "test.local", "hostname": "ipaserver.test.local", "ipa_python_version": 40800, "kdc": "ipaserver.test.local", "ntp_pool": null, "ntp_servers": null, "realm": "TEST.LOCAL", "servers": ["ipaserver.test.local"], "sssd": true}

TASK [ipaclient : Install - Cleanup leftover ccache] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:58
ok: [ipaserver.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}

TASK [ipaclient : Install - Configure NTP] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:63
ok: [ipaserver.test.local] => {"changed": false}

TASK [ipaclient : Install - Disable One-Time Password for on_master] ************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:75
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Test if IPA client has working krb5.keytab] *********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:80
ok: [ipaserver.test.local] => {"ca_crt_exists": true, "changed": false, "krb5_conf_ok": true, "krb5_keytab_ok": true, "ping_test_ok": false}

TASK [ipaclient : Install - Disable One-Time Password for client with working krb5.keytab] **************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:90
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Keytab or password is required for otp] *************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:105
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Get One-Time Password for client enrollment] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:113
skipping: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaclient : Install - Report error for OTP generation] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:133
skipping: [ipaserver.test.local] => {}

TASK [ipaclient : Install - Store the previously obtained OTP] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:139
skipping: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaclient : Install - Check if principal and keytab are set] **************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:157
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Check if one of password or keytabs are set] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:161
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Purge TEST.LOCAL from host keytab] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:169
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Backup and set hostname] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:182
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Join IPA] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:187
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:209
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:214
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:217
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Configure IPA default.conf] *************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:229
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Configure SSSD] *************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:238
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure krb5 for IPA realm] ***********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:255
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - IPA API calls for remaining enrollment parts] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:269
changed: [ipaserver.test.local] => {"ca_enabled": true, "changed": true, "subject_base": "O=TEST.LOCAL"}

TASK [ipaclient : Install - Fix IPA ca] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:277
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Create IPA NSS database] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:287
changed: [ipaserver.test.local] => {"ca_enabled_ra": true, "changed": true}

TASK [ipaclient : Install - Configure SSH and SSHD] *****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:313
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure automount] ********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:321
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure firefox] **********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:327
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Configure NIS] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:332
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaclient : Install - Restore original admin password if overwritten by OTP] **********************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:350
skipping: [ipaserver.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaclient : Cleanup leftover ccache] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:356
ok: [ipaserver.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}

TASK [ipaclient : Uninstall IPA client] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:16
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaserver : Install - Enable IPA] *****************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:400
changed: [ipaserver.test.local] => {"changed": true}

TASK [ipaserver : Install - Cleanup root IPA cache] *****************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:407
ok: [ipaserver.test.local] => {"changed": false, "path": "/root/.ipa_cache", "state": "absent"}

TASK [ipaserver : Install - Configure firewalld] ********************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:413
changed: [ipaserver.test.local] => {"changed": true, "cmd": ["firewall-cmd", "--permanent", "--add-service=freeipa-ldap", "--add-service=freeipa-ldaps", "--add-service=dns", "--add-service=ntp"], "delta": "0:00:00.375260", "end": "2019-09-06 12:07:02.865031", "rc": 0, "start": "2019-09-06 12:07:02.489771", "stderr": "", "stderr_lines": [], "stdout": "success", "stdout_lines": ["success"]}

TASK [ipaserver : Install - Configure firewalld runtime] ************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/install.yml:425
changed: [ipaserver.test.local] => {"changed": true, "cmd": ["firewall-cmd", "--add-service=freeipa-ldap", "--add-service=freeipa-ldaps", "--add-service=dns", "--add-service=ntp"], "delta": "0:00:00.464001", "end": "2019-09-06 12:07:03.773223", "rc": 0, "start": "2019-09-06 12:07:03.309222", "stderr": "", "stderr_lines": [], "stdout": "success", "stdout_lines": ["success"]}

TASK [ipaserver : Uninstall IPA server] *****************************************************************************
task path: /usr/share/ansible/roles/ipaserver/tasks/main.yml:16
skipping: [ipaserver.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
META: ran handlers
META: ran handlers

PLAY [Install IPA replicas] *****************************************************************************************

TASK [Gathering Facts] **********************************************************************************************
task path: /root/install-cluster.yml:10
ok: [ipareplica1.test.local]
META: ran handlers

TASK [ipareplica : Import variables specific to distribution] *******************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/main.yml:4
ok: [ipareplica1.test.local] => (item=/usr/share/ansible/roles/ipareplica/vars/RedHat-8.yml) => {"ansible_facts": {"ipareplica_packages": ["@idm:DL1/server"], "ipareplica_packages_adtrust": ["@idm:DL1/adtrust"], "ipareplica_packages_dns": ["@idm:DL1/dns"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipareplica/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipareplica/vars/RedHat-8.yml"}

TASK [ipareplica : Install IPA replica] *****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/main.yml:12
included: /usr/share/ansible/roles/ipareplica/tasks/install.yml for ipareplica1.test.local

TASK [ipareplica : Install - Ensure IPA replica packages are installed] *********************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:6
changed: [ipareplica1.test.local] => {"changed": true, "msg": "", "rc": 0, "results": ["Module idm:DL1/server installed.", "Installed: sssd-tools-2.2.0-18.el8.x86_64", "Installed: 
	*
	*
	*
TASK [ipareplica : Install - Ensure IPA replica packages for dns are installed] *************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:11
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipareplica : Install - Ensure IPA replica packages for adtrust are installed] *********************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:17
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipareplica : Install - Set ipareplica_servers] ****************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:28
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipareplica : Install - Set default principal if no keytab is given] *******************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:33
ok: [ipareplica1.test.local] => {"ansible_facts": {"ipaadmin_principal": "admin"}, "changed": false}

TASK [ipareplica : Install - Replica installation test] *************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:38
ok: [ipareplica1.test.local] => {"change_master_for_certmonger": true, "changed": false, "client_enrolled": false, "domain": "test.local", "hostname": "ipareplica1.test.local", "ipa_python_version": 40800, "realm": "TEST.LOCAL", "server": null, "setup_adtrust": false, "setup_kra": false}

TASK [Install - Setup client] ***************************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:81

TASK [ipaclient : Import variables specific to distribution] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:4
ok: [ipareplica1.test.local] => (item=/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml) => {"ansible_facts": {"ipaclient_packages": ["@idm:DL1/client"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"}

TASK [ipaclient : Install IPA client] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:12
included: /usr/share/ansible/roles/ipaclient/tasks/install.yml for ipareplica1.test.local

TASK [ipaclient : Install - Ensure that IPA client packages are installed] ******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:4
ok: [ipareplica1.test.local] => {"changed": false, "msg": "Nothing to do", "rc": 0, "results": []}

TASK [ipaclient : Install - Set ipaclient_servers] ******************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:13
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Set ipaclient_servers from cluster inventory] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:18
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Check that either principal or keytab is set] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:24
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Set default principal if no keytab is given] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:28
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - IPA client test] ************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:33
ok: [ipareplica1.test.local] => {"basedn": "dc=test,dc=local", "changed": false, "client_already_configured": false, "client_domain": "test.local", "dnsok": true, "domain": "test.local", "hostname": "ipareplica1.test.local", "ipa_python_version": 40800, "kdc": "ipaserver.test.local", "ntp_pool": null, "ntp_servers": null, "realm": "TEST.LOCAL", "servers": ["ipaserver.test.local"], "sssd": true}

TASK [ipaclient : Install - Cleanup leftover ccache] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:58
ok: [ipareplica1.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}

TASK [ipaclient : Install - Configure NTP] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:63
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipaclient : Install - Disable One-Time Password for on_master] ************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:75
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Test if IPA client has working krb5.keytab] *********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:80
ok: [ipareplica1.test.local] => {"ca_crt_exists": false, "changed": false, "krb5_conf_ok": false, "krb5_keytab_ok": false, "ping_test_ok": false}

TASK [ipaclient : Install - Disable One-Time Password for client with working krb5.keytab] **************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:90
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Keytab or password is required for otp] *************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:105
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Get One-Time Password for client enrollment] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:113
skipping: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaclient : Install - Report error for OTP generation] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:133
skipping: [ipareplica1.test.local] => {}

TASK [ipaclient : Install - Store the previously obtained OTP] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:139
skipping: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaclient : Install - Check if principal and keytab are set] **************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:157
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Check if one of password or keytabs are set] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:161
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Purge TEST.LOCAL from host keytab] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:169
changed: [ipareplica1.test.local] => {"changed": true, "cmd": ["/usr/sbin/ipa-rmkeytab", "-k", "/etc/krb5.keytab", "-r", "TEST.LOCAL"], "delta": "0:00:00.004798", "end": "2019-09-06 12:08:12.561831", "failed_when_result": false, "msg": "non-zero return code", "rc": 3, "start": "2019-09-06 12:08:12.557033", "stderr": "Failed to open keytab '/etc/krb5.keytab': No such file or directory", "stderr_lines": ["Failed to open keytab '/etc/krb5.keytab': No such file or directory"], "stdout": "", "stdout_lines": []}

TASK [ipaclient : Install - Backup and set hostname] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:182
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipaclient : Install - Join IPA] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:187
changed: [ipareplica1.test.local] => {"already_joined": false, "changed": true}

TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:209
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:214
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:217
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Configure IPA default.conf] *************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:229
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure SSSD] *************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:238
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure krb5 for IPA realm] ***********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:255
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipaclient : Install - IPA API calls for remaining enrollment parts] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:269
changed: [ipareplica1.test.local] => {"ca_enabled": true, "changed": true, "subject_base": "O=TEST.LOCAL"}

TASK [ipaclient : Install - Fix IPA ca] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:277
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Create IPA NSS database] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:287
changed: [ipareplica1.test.local] => {"ca_enabled_ra": true, "changed": true}

TASK [ipaclient : Install - Configure SSH and SSHD] *****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:313
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure automount] ********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:321
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure firefox] **********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:327
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Configure NIS] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:332
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipaclient : Install - Restore original admin password if overwritten by OTP] **********************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:350
skipping: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaclient : Cleanup leftover ccache] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:356
ok: [ipareplica1.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}

TASK [ipaclient : Uninstall IPA client] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:16
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipareplica : Install - Configure firewalld] *******************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:95
changed: [ipareplica1.test.local] => {"changed": true, "cmd": ["firewall-cmd", "--permanent", "--add-service=freeipa-ldap", "--add-service=freeipa-ldaps", "--add-service=ntp"], "delta": "0:00:00.377143", "end": "2019-09-06 12:08:34.508746", "rc": 0, "start": "2019-09-06 12:08:34.131603", "stderr": "", "stderr_lines": [], "stdout": "success", "stdout_lines": ["success"]}

TASK [ipareplica : Install - Configure firewalld runtime] ***********************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:107
changed: [ipareplica1.test.local] => {"changed": true, "cmd": ["firewall-cmd", "--add-service=freeipa-ldap", "--add-service=freeipa-ldaps", "--add-service=ntp"], "delta": "0:00:00.415088", "end": "2019-09-06 12:08:35.440946", "rc": 0, "start": "2019-09-06 12:08:35.025858", "stderr": "", "stderr_lines": [], "stdout": "success", "stdout_lines": ["success"]}

TASK [ipareplica : Install - Replica preparation] *******************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:118
changed: [ipareplica1.test.local] => {"_add_to_ipaservers": true, "_ca_enabled": true, "_ca_file": "/etc/ipa/ca.crt", "_ca_subject": "CN=Certificate Authority,O=TEST.LOCAL", "_dirsrv_ca_cert": null, "_dirsrv_pkcs12_file": null, "_dirsrv_pkcs12_info": null, "_http_ca_cert": null, "_http_pkcs12_file": null, "_http_pkcs12_info": null, "_kra_enabled": false, "_pkinit_ca_cert": null, "_pkinit_pkcs12_file": null, "_pkinit_pkcs12_info": null, "_subject_base": "O=TEST.LOCAL", "_top_dir": "/tmp/tmpqxh5lpceipa", "adtrust_netbios_name": null, "adtrust_reset_netbios_name": false, "ccache": "/tmp/krbccb5itlmmn/ccache", "changed": true, "config_ca_host_name": "ipaserver.test.local", "config_ips": ["10.16.56.179"], "config_kra_host_name": "ipaserver.test.local", "config_master_host_name": "ipaserver.test.local", "config_setup_ca": false, "dns_ip_addresses": [], "dns_reverse_zones": [], "forward_policy": null, "installer_ccache": "/tmp/tmpajr0ol72", "no_dnssec_validation": null, "rid_base": 1000, "secondary_rid_base": 100000000, "subject_base": "O=TEST.LOCAL"}

TASK [ipareplica : Install - Add to ipaservers] *********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:173
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Create dirman password] ****************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:185
changed: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": true}

TASK [ipareplica : Install - Set dirman password] *******************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:191
ok: [ipareplica1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipareplica : Install - Setup certmonger] **********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:197
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Install CA certs] **********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:201
changed: [ipareplica1.test.local] => {"changed": true, "config_ca_host_name": "ipaserver.test.local", "config_master_host_name": "ipaserver.test.local"}

TASK [ipareplica : Install - Setup DS] ******************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:241
changed: [ipareplica1.test.local] => {"changed": true, "ds_ca_subject": "CN=Certificate Authority,O=TEST.LOCAL", "ds_suffix": "dc=test,dc=local"}

TASK [ipareplica : Install - Create IPA conf] ***********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:285
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Setup KRB] *****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:323
changed: [ipareplica1.test.local] => {"changed": true, "config_master_host_name": "ipaserver.test.local"}

TASK [ipareplica : Install - Create override IPA conf] **************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:341
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - DS enable SSL] *************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:382
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Setup http] ****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:402
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Create original IPA conf again] ********************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:423
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Setup otpd] ****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:462
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Setup custodia] ************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:479
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Setup CA] ******************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:500
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - KRB enable SSL] ************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:529
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - DS apply updates] **********************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:547
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Setup kra] *****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:568
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipareplica : Install - Restart KDC] ***************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:607
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Custodia import dm password] ***********************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:624
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Promote SSSD] **************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:646
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Promote openldap.conf] *****************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:659
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Setup DNS] *****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:672
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Setup adtrust] *************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:696
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipareplica : Install - Enable IPA] ****************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:718
changed: [ipareplica1.test.local] => {"changed": true}

TASK [ipareplica : Install - Cleanup root IPA cache] ****************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/install.yml:735
ok: [ipareplica1.test.local] => {"changed": false, "path": "/root/.ipa_cache", "state": "absent"}

TASK [ipareplica : Uninstall IPA replica] ***************************************************************************
task path: /usr/share/ansible/roles/ipareplica/tasks/main.yml:16
skipping: [ipareplica1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
META: ran handlers
META: ran handlers

PLAY [Install IPA clients] ******************************************************************************************

TASK [Gathering Facts] **********************************************************************************************
task path: /root/install-cluster.yml:18
ok: [ipaclient1.test.local]
META: ran handlers

TASK [ipaclient : Import variables specific to distribution] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:4
ok: [ipaclient1.test.local] => (item=/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml) => {"ansible_facts": {"ipaclient_packages": ["@idm:DL1/client"]}, "ansible_included_var_files": ["/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"], "ansible_loop_var": "item", "changed": false, "item": "/usr/share/ansible/roles/ipaclient/vars/RedHat-8.yml"}

TASK [ipaclient : Install IPA client] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:12
included: /usr/share/ansible/roles/ipaclient/tasks/install.yml for ipaclient1.test.local

TASK [ipaclient : Install - Ensure that IPA client packages are installed] ******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:4
changed: [ipaclient1.test.local] => {"changed": true, "msg": "", "rc": 0, "results": ["Module idm:DL1/client installed.", "Installed: ipa-client-4.8.0-10.module+el8.1.0+4098+f286395e.x86_64", "Installed: python3-qrcode-core-5.1-12.module+el8.1.0+4098+f286395e.noarch", "Installed: ipa-client-common-4.8.0-10.module+el8.1.0+4098+f286395e.noarch", "Installed: 
	*
	*
	*
	*
TASK [ipaclient : Install - Set ipaclient_servers] ******************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:13
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Set ipaclient_servers from cluster inventory] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:18
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Check that either principal or keytab is set] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:24
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Set default principal if no keytab is given] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:28
ok: [ipaclient1.test.local] => {"ansible_facts": {"ipaadmin_principal": "admin"}, "changed": false}

TASK [ipaclient : Install - IPA client test] ************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:33
ok: [ipaclient1.test.local] => {"basedn": "dc=test,dc=local", "changed": false, "client_already_configured": false, "client_domain": "test.local", "dnsok": true, "domain": "test.local", "hostname": "ipaclient1.test.local", "ipa_python_version": 40800, "kdc": "ipareplica1.test.local,ipaserver.test.local", "ntp_pool": null, "ntp_servers": null, "realm": "TEST.LOCAL", "servers": ["ipareplica1.test.local"], "sssd": true}

TASK [ipaclient : Install - Cleanup leftover ccache] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:58
ok: [ipaclient1.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}

TASK [ipaclient : Install - Configure NTP] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:63
changed: [ipaclient1.test.local] => {"changed": true}

TASK [ipaclient : Install - Disable One-Time Password for on_master] ************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:75
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Test if IPA client has working krb5.keytab] *********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:80
ok: [ipaclient1.test.local] => {"ca_crt_exists": false, "changed": false, "krb5_conf_ok": false, "krb5_keytab_ok": false, "ping_test_ok": false}

TASK [ipaclient : Install - Disable One-Time Password for client with working krb5.keytab] **************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:90
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Keytab or password is required for otp] *************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:105
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Get One-Time Password for client enrollment] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:113
skipping: [ipaclient1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaclient : Install - Report error for OTP generation] ********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:133
skipping: [ipaclient1.test.local] => {}

TASK [ipaclient : Install - Store the previously obtained OTP] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:139
skipping: [ipaclient1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaclient : Install - Check if principal and keytab are set] **************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:157
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Check if one of password or keytabs are set] ********************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:161
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Purge TEST.LOCAL from host keytab] ******************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:169
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Backup and set hostname] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:182
changed: [ipaclient1.test.local] => {"changed": true}

TASK [ipaclient : Install - Join IPA] *******************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:187
changed: [ipaclient1.test.local] => {"already_joined": false, "changed": true}

TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:209
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:214
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : fail] *********************************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:217
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Configure IPA default.conf] *************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:229
changed: [ipaclient1.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure SSSD] *************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:238
changed: [ipaclient1.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure krb5 for IPA realm] ***********************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:255
changed: [ipaclient1.test.local] => {"changed": true}

TASK [ipaclient : Install - IPA API calls for remaining enrollment parts] *******************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:269
changed: [ipaclient1.test.local] => {"ca_enabled": true, "changed": true, "subject_base": "O=TEST.LOCAL"}

TASK [ipaclient : Install - Fix IPA ca] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:277
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Create IPA NSS database] ****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:287
changed: [ipaclient1.test.local] => {"ca_enabled_ra": true, "changed": true}

TASK [ipaclient : Install - Configure SSH and SSHD] *****************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:313
changed: [ipaclient1.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure automount] ********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:321
changed: [ipaclient1.test.local] => {"changed": true}

TASK [ipaclient : Install - Configure firefox] **********************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:327
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}

TASK [ipaclient : Install - Configure NIS] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:332
changed: [ipaclient1.test.local] => {"changed": true}

TASK [ipaclient : Install - Restore original admin password if overwritten by OTP] **********************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:350
skipping: [ipaclient1.test.local] => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result", "changed": false}

TASK [ipaclient : Cleanup leftover ccache] **************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/install.yml:356
ok: [ipaclient1.test.local] => {"changed": false, "path": "/etc/ipa/.dns_ccache", "state": "absent"}

TASK [ipaclient : Uninstall IPA client] *****************************************************************************
task path: /usr/share/ansible/roles/ipaclient/tasks/main.yml:16
skipping: [ipaclient1.test.local] => {"changed": false, "skip_reason": "Conditional result was False"}
META: ran handlers
META: ran handlers

PLAY RECAP **********************************************************************************************************
ipaclient1.test.local      : ok=20   changed=12   unreachable=0    failed=0    skipped=19   rescued=0    ignored=0   
ipareplica1.test.local     : ok=52   changed=38   unreachable=0    failed=0    skipped=25   rescued=0    ignored=0   
ipaserver.test.local       : ok=37   changed=22   unreachable=0    failed=0    skipped=29   rescued=0    ignored=0   



Based on the above observation, marking the bug VERIFIED

Comment 12 errata-xmlrpc 2019-11-05 21:09:05 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2019:3418