#5308 Unable to establish winsync replication
Closed: Fixed Opened by pvoborni.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1262315

Description of problem:
Winsync replication fails with error
unexpected error: {'desc': 'Object class violation'}
Version-Release number of selected component (if applicable):
# rpm -q ipa-server
ipa-server-4.2.0-9.el7.x86_64
How reproducible:
Always
Steps to Reproduce:
1. Setup winync replication
2.
3.
Actual results:
:: [  BEGIN   ] :: Creating Winsync Agreement with valid cert :: actually
running 'ipa-replica-manage connect --winsync --passsync=password
--cacert=/tmp/tmp.GqgBmxLgKR/ADcert.cer squab.adrelm.com --binddn
"CN=Administrator,CN=Users,DC=adrelm,DC=com" --bindpw Secret123 -v -p Secret123
> /tmp/tmp.GqgBmxLgKR/tmpout.ipa_winsync_0003.out 2>&1'
:: [   FAIL   ] :: Creating Winsync Agreement with valid cert (Expected 0, got
1)
ipa: INFO: AD Suffix is: DC=adrelm,DC=com
Added CA certificate /tmp/tmp.GqgBmxLgKR/ADcert.cer to certificate database for
vm-idm-008.syncwin.test
The user for the Windows PassSync service is
uid=passsync,cn=sysaccounts,cn=etc,dc=syncwin,dc=test
Adding Windows PassSync system account
unexpected error: {'desc': 'Object class violation'}
[root@vm-idm-008 sgoveas]# tail -100 /var/log/dirsrv/slapd-SYNCWIN-TEST/errors
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_ECDH_RSA_WITH_AES_256_CBC_SHA: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_RSA_WITH_AES_256_GCM_SHA384: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:     TLS_RSA_WITH_AES_256_CBC_SHA:
enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_RSA_WITH_AES_256_CBC_SHA256: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_RSA_WITH_AES_128_GCM_SHA256: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:     TLS_RSA_WITH_AES_128_CBC_SHA:
enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_RSA_WITH_AES_128_CBC_SHA256: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA: enabled
[11/Sep/2015:16:07:30 +051800] - SSL alert:     TLS_RSA_WITH_SEED_CBC_SHA:
enabled
[11/Sep/2015:16:07:30 +051800] SSL Initialization - Configured SSL version
range: min: TLS1.0, max: TLS1.2
[11/Sep/2015:16:07:30 +051800] - 389-Directory/1.3.4.0 B2015.247.1833 starting
up
[11/Sep/2015:16:07:30 +051800] schema-compat-plugin - warning: no entries set
up under cn=computers, cn=compat,dc=syncwin,dc=test
[11/Sep/2015:16:07:30 +051800] schema-compat-plugin - warning: no entries set
up under cn=ng, cn=compat,dc=syncwin,dc=test
[11/Sep/2015:16:07:30 +051800] schema-compat-plugin - warning: no entries set
up under ou=sudoers,dc=syncwin,dc=test
[11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target
cn=groups,cn=compat,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target
cn=computers,cn=compat,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target
cn=ng,cn=compat,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target
ou=sudoers,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target
cn=users,cn=compat,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target
cn=ad,cn=etc,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=casigningcert
cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=casigningcert
cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:07:30 +051800] NSACLPlugin - The ACL target cn=automember
rebuild membership,cn=tasks,cn=config does not exist
[11/Sep/2015:16:07:30 +051800] - Skipping CoS Definition cn=Password
Policy,cn=accounts,dc=syncwin,dc=test--no CoS Templates found, which should be
added before the CoS Definition.
[11/Sep/2015:16:07:30 +051800] - slapd started.  Listening on All Interfaces
port 389 for LDAP requests
[11/Sep/2015:16:07:30 +051800] - Listening on All Interfaces port 636 for LDAPS
requests
[11/Sep/2015:16:07:30 +051800] - Listening on
/var/run/slapd-SYNCWIN-TEST.socket for LDAPI requests
[11/Sep/2015:16:44:19 +051800] - slapd shutting down - signaling operation
threads - op stack size 2 max work q size 1 max work q stack size 1
[11/Sep/2015:16:44:19 +051800] - slapd shutting down - waiting for 27 threads
to terminate
[11/Sep/2015:16:44:19 +051800] - slapd shutting down - closing down internal
subsystems and plugins
[11/Sep/2015:16:44:20 +051800] - Waiting for 4 database threads to stop
[11/Sep/2015:16:44:21 +051800] - All database threads now stopped
[11/Sep/2015:16:44:21 +051800] - slapd shutting down - freed 1 work q stack
objects - freed 4 op stack objects
[11/Sep/2015:16:44:21 +051800] - slapd stopped.
[11/Sep/2015:16:44:22 +051800] - SSL alert: Configured NSS Ciphers
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_DSS_WITH_AES_256_GCM_SHA384: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_RSA_WITH_AES_256_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_DSS_WITH_AES_256_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_DSS_WITH_AES_256_CBC_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_DSS_WITH_AES_128_GCM_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_RSA_WITH_AES_128_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_DSS_WITH_AES_128_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_DSS_WITH_AES_128_CBC_SHA256: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_ECDH_RSA_WITH_AES_256_CBC_SHA: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:
TLS_RSA_WITH_AES_256_GCM_SHA384: enabled
[11/Sep/2015:16:44:22 +051800] - SSL alert:     TLS_RSA_WITH_AES_256_CBC_SHA:
enabled
[11/Sep/2015:16:44:23 +051800] - SSL alert:
TLS_RSA_WITH_AES_256_CBC_SHA256: enabled
[11/Sep/2015:16:44:23 +051800] - SSL alert:
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA: enabled
[11/Sep/2015:16:44:23 +051800] - SSL alert:
TLS_RSA_WITH_AES_128_GCM_SHA256: enabled
[11/Sep/2015:16:44:23 +051800] - SSL alert:     TLS_RSA_WITH_AES_128_CBC_SHA:
enabled
[11/Sep/2015:16:44:23 +051800] - SSL alert:
TLS_RSA_WITH_AES_128_CBC_SHA256: enabled
[11/Sep/2015:16:44:23 +051800] - SSL alert:
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA: enabled
[11/Sep/2015:16:44:23 +051800] - SSL alert:     TLS_RSA_WITH_SEED_CBC_SHA:
enabled
[11/Sep/2015:16:44:23 +051800] SSL Initialization - Configured SSL version
range: min: TLS1.0, max: TLS1.2
[11/Sep/2015:16:44:23 +051800] - 389-Directory/1.3.4.0 B2015.247.1833 starting
up
[11/Sep/2015:16:44:23 +051800] schema-compat-plugin - warning: no entries set
up under cn=computers, cn=compat,dc=syncwin,dc=test
[11/Sep/2015:16:44:23 +051800] schema-compat-plugin - warning: no entries set
up under cn=ng, cn=compat,dc=syncwin,dc=test
[11/Sep/2015:16:44:23 +051800] schema-compat-plugin - warning: no entries set
up under ou=sudoers,dc=syncwin,dc=test
[11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target
cn=groups,cn=compat,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target
cn=computers,cn=compat,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target
cn=ng,cn=compat,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target
ou=sudoers,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target
cn=users,cn=compat,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target
cn=ad,cn=etc,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=casigningcert
cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=casigningcert
cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=syncwin,dc=test does not exist
[11/Sep/2015:16:44:23 +051800] NSACLPlugin - The ACL target cn=automember
rebuild membership,cn=tasks,cn=config does not exist
[11/Sep/2015:16:44:23 +051800] - Skipping CoS Definition cn=Password
Policy,cn=accounts,dc=syncwin,dc=test--no CoS Templates found, which should be
added before the CoS Definition.
[11/Sep/2015:16:44:23 +051800] - slapd started.  Listening on All Interfaces
port 389 for LDAP requests
[11/Sep/2015:16:44:23 +051800] - Listening on All Interfaces port 636 for LDAPS
requests
[11/Sep/2015:16:44:23 +051800] - Listening on
/var/run/slapd-SYNCWIN-TEST.socket for LDAPI requests
[11/Sep/2015:16:44:24 +051800] - Entry
"uid=passsync,cn=sysaccounts,cn=etc,dc=syncwin,dc=test" -- attribute "memberOf"
not allowed
[11/Sep/2015:16:44:24 +051800] memberof-plugin - memberof_postop_modify: failed
to replace values in  dn (cn=PassSync
Service,cn=privileges,cn=pbac,dc=syncwin,dc=test).  Error (65)
Expected results:
Winsync replication is establised
Additional info:

The ticket was cloned just for tracking purposes.

ipa-4-2:

  • ffb676511054e72b05b25a8f339a15da5b40eb2f

master:

  • 73c82d00736ae032465b7e50a2ea51ad753c8093

Metadata Update from @pvoborni:
- Issue assigned to someone
- Issue set to the milestone: FreeIPA 4.2.2

Metadata